SUNBURST Backdoor Exploits SolarWinds Supply Chain Vulnerability
ID: 896eb714-5b92-5ffe-b77b-b42dbaaba38f
STIX ID: report--896eb714-5b92-5ffe-b77b-b42dbaaba38f
Feed Name: ThreatCluster
The SUNBURST campaign involved trojanized SolarWinds Orion updates (March–May 2020) that dropped a malicious DLL (SolarWinds.Orion.Core.BusinessLayer.dll) acting as a backdoor which communicated with C2 servers while blending into legitimate traffic; it remained dormant for up to two weeks before executing commands. Victims spanned government, consulting, technology, and telecom organizations across multiple regions, and the operation is attributed to the state-sponsored group APT29 (UNC2452). FireEye discovered and continues monitoring the incident and has notified affected entities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
