logo

Supply Chain Exploitation of SolarWinds Orion Software | Huntress

ID: 16cb645f-d4ca-5629-9a41-136eea2f70b5

STIX ID: report--16cb645f-d4ca-5629-9a41-136eea2f70b5

Feed Name: Huntress Blog

Threat Score
92/100

Date Published: 2024-04-12

Date Updated: 2026-04-28

...
...

FireEye and others discovered a SolarWinds Orion supply-chain compromise (SUNBURST/Solorigate) in which malicious, digitally-signed Orion updates (notably SolarWinds.Orion.Core.BusinessLayer.dll) were distributed between March and June 2020, enabling stealthy backdoor access, C2 communications, and in some cases administrative access and SAML token signing compromise; the report includes mitigation guidance, detection updates, and filesystem locations/IOCs for hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.