logo

SUNBURST Backdoor Exploits SolarWinds Supply Chain Vulnerability

ID: 896eb714-5b92-5ffe-b77b-b42dbaaba38f

STIX ID: report--896eb714-5b92-5ffe-b77b-b42dbaaba38f

Feed Name: ThreatCluster

Threat Score
95/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

...
...

The SUNBURST campaign involved trojanized SolarWinds Orion updates (March–May 2020) that dropped a malicious DLL (SolarWinds.Orion.Core.BusinessLayer.dll) acting as a backdoor which communicated with C2 servers while blending into legitimate traffic; it remained dormant for up to two weeks before executing commands. Victims spanned government, consulting, technology, and telecom organizations across multiple regions, and the operation is attributed to the state-sponsored group APT29 (UNC2452). FireEye discovered and continues monitoring the incident and has notified affected entities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.