SolarWinds Compromise

Campaign updated 8 months ago (2024-01-10T14:25:38.971Z)
Download STIX
Preview STIX
The SolarWinds compromise, a highly sophisticated cyber attack campaign, was first brought to light by FireEye in December 2020. The attackers leveraged a supply chain vulnerability in the SolarWinds Orion software, installing a malicious backdoor known as SUNBURST. This allowed them to gain access to numerous organizations' systems, potentially undetected for a significant period of time. FireEye's initial report also identified indicators for a webshell they named SUPERNOVA, adding another layer to the complexity and severity of the attack. According to SecurityScorecard, the initial timing of the SolarWinds compromise may have been significantly earlier than initially suspected, possibly beginning up to five months prior to its discovery. This extended timeframe increased the potential impact and reach of the attack, providing the attackers with a longer window to infiltrate and exploit the targeted systems. During this time, the attackers could have gathered sensitive information, disrupted operations, or caused other forms of damage. A report from Volexity named the threat actor behind the SolarWinds compromise as Dark Halo. They exploited the SolarWinds breach to infiltrate various organizations, further demonstrating the widespread implications of this attack. In response to these revelations, the Cybersecurity & Infrastructure Security Agency (CISA) released supplemental guidance and updates on emergency directives aimed at mitigating the effects of the SolarWinds compromise. These actions underscored the critical importance of robust cybersecurity measures and swift responses to such incidents.
Description last updated: 2023-12-20T17:31:09.036Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the SolarWinds Compromise Campaign was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
MITRE
9 months ago
SolarStorm Supply Chain Attack Timeline