logo

Additional Analysis into the SUNBURST Backdoor

ID: 051d794e-b010-5ff9-abe0-41bae6d2f3f8

STIX ID: report--051d794e-b010-5ff9-abe0-41bae6d2f3f8

Feed Name: McAfee Labs Blog

Threat Score
92/100

Date Published: 2020-12-17

Date Updated: 2026-04-28

Author: Christiaan Beek

...
...

Executive summary: This McAfee ATR analysis examines the SUNBURST backdoor embedded in SolarWinds.Orion.Core.BusinessLayer.dll, describing how it establishes persistence and stealth via long dormancy, a hardcoded named pipe, system fingerprinting (MD5 UID), service/registry manipulation, extensive system and network reconnaissance, proxy credential harvesting, and DGA-based C2 communications (subdomains of avsvmcloud.com with listed examples and CNAMEs); it highlights indicators and urges further remediation to detect any additional persistence mechanisms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.