logo

SUNBURST Backdoor Exploits SolarWinds Supply Chain Vulnerability

ID: 034d01c1-aa1e-5872-ae9c-915372899cda

STIX ID: report--034d01c1-aa1e-5872-ae9c-915372899cda

Feed Name: ThreatCluster

Threat Score
95/100

Date Published: 2026-06-16

Date Updated: 2026-06-22

...
...

The SUNBURST backdoor, attributed to state-sponsored APT29, was delivered through malicious SolarWinds Orion updates between March and May 2020; the trojanized SolarWinds.Orion.Core.BusinessLayer.dll communicated with C2 servers while mimicking legitimate traffic, remained dormant for up to two weeks, and impacted numerous government and private organizations globally.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.