Cyber-attack Timeline: SolarWinds

Educational & easy-to consume visual guides to understanding attacks & enhancing resilience

Solarwinds Timeline Cover Solarwinds Timeline Summary

Download Our Educational Cyber-Attack Timeline on the massive SolarWinds Supply Chain Attack

At Cyber Management Alliance, Incident Response is our passion. We study and analyse cyber-attacks to create informational visual timelines which can be easily read for educational purposes and to enhance cyber resilience.

For the SolarWinds cyber-attack, also known as the Solorigate attack, we have created a visual timeline and an accompanying detailed report.  Download it now. 

Don't forget to read our blog on the SolarWinds Supply Chain Attack.

Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.

  • ** GDPR ** We wholeheartedly believe your and our rights to privacy and in the GDPR. The bottom of the page explains how we use your data. 
  • Align with the GDPR requirements.
  • Increase your Breach Readiness.
  • Reduce your time to detect and respond.

Complete the form below to receive a copy of the detailed SolarWinds attack document and timeline.

cyber-essentials-certification
NCSC Certified Training B&W 300px
CSC

FAQs on the SolarWinds Attack

  • 1. What happened in the SolarWinds cyber attack?

    The SolarWinds cyber attack, also known as Solorigate or the Sunburst attack, was a sophisticated supply chain attack publicly disclosed in December 2020. Suspected nation-state hackers compromised the build process of SolarWinds' Orion IT monitoring software and inserted a backdoor known as SUNBURST into legitimate, digitally signed software updates. Around 18,000 SolarWinds customers downloaded the trojanised Orion updates released between March and June 2020, although only a much smaller number were selected for active follow-on intrusion. Victims included multiple US federal agencies and major technology companies, making it one of the most significant cyber-espionage campaigns ever uncovered.

  • 2. When did the SolarWinds cyber attack take place?

    Investigators traced the earliest intrusion activity to January 2019, when the attackers carried out very early reconnaissance. They ran a trial run of their code injection from September 2019, injected the SUNBURST backdoor into the Orion source code in February 2020, and SolarWinds released the poisoned hotfix on 26 March 2020. The breach was not discovered until December 2020: FireEye disclosed its own breach on 8 December 2020, and SolarWinds publicly confirmed the supply chain compromise on 13 December 2020. The attackers therefore had access for close to two years before detection.

  • 3. Who was behind the SolarWinds cyber attack?

    The attack was attributed to a nation-state group. In April 2021, the US government (NSA, FBI and CISA), together with the UK's NCSC, formally attributed the campaign to actors associated with Russia's Foreign Intelligence Service (SVR), also tracked as APT29, Cozy Bear and The Dukes. Before formal attribution, the threat actor was tracked under names including UNC2452 (by FireEye), Dark Halo (by Volexity) and SolarStorm (by Palo Alto Unit 42). Russia denied responsibility, and some early speculation pointed elsewhere, but the consensus of US and UK intelligence agencies pointed to Russian state-sponsored actors.

  • 4. How did the SolarWinds supply chain attack work?

    The attackers compromised SolarWinds' software build environment and used a tool called SUNSPOT to insert the SUNBURST backdoor into the source code of the Orion platform. The malicious code was then compiled, digitally signed with a valid SolarWinds certificate and distributed to customers through the company's normal, trusted software update process. Because the update appeared legitimate, organisations unknowingly installed the backdoor. After lying dormant for around two weeks, it could communicate with command-and-control infrastructure and, against selected high-value targets, deploy further malware such as TEARDROP and Cobalt Strike BEACON and escalate privileges within the network.

  • 5. What malware was used in the SolarWinds attack?

    Several pieces of malware were linked to the campaign. SUNSPOT was used to inject the backdoor during the build process; SUNBURST (also called Solorigate) was the backdoor distributed through Orion updates; TEARDROP was a memory-only dropper used to deploy Cobalt Strike BEACON against high-value targets; and RAINDROP was a related loader found at some victims. A separate piece of malware called SUPERNOVA, linked to the vulnerability CVE-2020-10148, was found on some Orion servers but was assessed as not part of the original supply chain attack. Later related activity was tied to malware tracked as NOBELIUM and SUNSHUTTLE.

  • 6. How many organisations were affected by the SolarWinds hack?

    SolarWinds estimated that fewer than 18,000 customers installed the Orion updates containing the SUNBURST backdoor. However, only a much smaller subset was selected for active, follow-on intrusion. US officials later stated that around nine federal government agencies and roughly 100 private-sector companies were compromised through additional, targeted activity. Affected organisations spanned government, technology, consulting, telecoms and energy across North America, Europe, Asia and the Middle East.

  • 7. Who were the victims of the SolarWinds attack?

    Reported victims included numerous US federal agencies, among them the Departments of the Treasury, Commerce, State, Homeland Security, Justice and Energy (including the National Nuclear Security Administration), as well as NASA, the National Institutes of Health and the Federal Aviation Administration. Technology and security companies named in reporting included FireEye, Microsoft, Cisco, Intel, Nvidia, VMware, Deloitte and Mimecast. Victims were also confirmed in several other countries beyond the United States.

  • 8. What data was accessed in the SolarWinds breach?

    Because the campaign was an intelligence-gathering operation, the attackers focused on email and internal data at selected targets. Reporting indicated that they monitored internal email traffic at agencies such as the US Treasury and Commerce departments, accessed Office 365 mailboxes (the Department of Justice said around 3% of its mailboxes were potentially accessed), and in Microsoft's case viewed some internal source code repositories. The full scope of data taken was never completely disclosed, and several affected organisations said they found no evidence that production systems or customer data had been compromised.

  • 9. Was a ransom paid, and how much did the SolarWinds attack cost?

    No ransom was involved: this was an espionage campaign rather than a ransomware attack, so there was no ransom demand or payment, and no operational downtime was reported. SolarWinds disclosed around $3.5 million in expenses related to the incident in its early filings, covering investigation, remediation, legal and consulting costs, with further costs expected. The company also faced shareholder class-action lawsuits, a share price fall of roughly 17% to 22% after disclosure, and significant reputational damage.

  • 10. How was the SolarWinds hack discovered?

    The campaign came to light through the cybersecurity firm FireEye. On 8 December 2020, FireEye disclosed that it had been breached and that attackers had stolen its Red Team tools. While investigating its own compromise, FireEye traced the intrusion to a backdoor in SolarWinds' Orion software, reviewing around 50,000 lines of source code to confirm it, and then notified SolarWinds and law enforcement. SolarWinds publicly confirmed the supply chain compromise on 13 December 2020. Many analysts noted that the breach might have gone undetected for much longer had FireEye itself not been targeted.

  • 11. How did SolarWinds and the US government respond to the attack?

    SolarWinds released hotfix updates to replace the compromised component, engaged external cybersecurity specialists, and worked with FireEye, the FBI and the intelligence community. The US Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive 21-01 ordering federal agencies to disconnect affected Orion products, and a Cyber Unified Coordination Group was established to coordinate the government-wide response. Microsoft and industry partners sinkholed key attacker infrastructure, and in April 2021 the US imposed sanctions on Russia over the campaign.

  • 12. What can organisations learn from the SolarWinds cyber attack?

    The SolarWinds incident is a landmark example of supply chain risk: trusted, signed software updates became the delivery mechanism for a sophisticated backdoor that bypassed traditional defences. The key lessons are to scrutinise the security of software build pipelines and third-party vendors, to monitor for anomalous behaviour rather than relying solely on signatures, to apply network segmentation and least-privilege access, and to maintain tested incident response plans for stealthy, long-dwell intrusions. Cyber Management Alliance helps organisations build these capabilities through training, cyber crisis tabletop exercises and incident response planning.

We are industry experienced practitioners when it comes to cyber security training & cyber security consultancy services

1487652208_graduationcap

Training

We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.

1487652701_like

Virtual CISO Services

Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.

1487652784_calendar-3

Virtual Cyber Assistant

A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.

1487652846_microphone

Cyber Crisis Tabletop Exercises

Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.

1487652632_search

Ransomware Tabletop Exercise

Measure your organisation’s Ransomware Readiness with a unique blend of verbal and visual simulations and ransomware scenario walkthroughs.

1487652567_line-chart

Executive Cyber Awareness Sessions

Specially designed for executive management, CEOs and boards of directors, engaging them in a business context to help explain the threats and risks from cyber-attacks.

How we use your data:

  • The form above collects personal information so we may email you the requested information and pressing the "Get your free copy now"  button acts as informed consent for this processing purpose. Consequently we may be in touch to:

    • Update you when we host our ground-breaking Wisdom of Crowds events in your country or region.
    • Keep you posted on free resources and documents around Wisdom of Crowds events and its outputs. (For example, we tend to create insightful mind maps and we also are the creators of free to view Insights with Cyber Leaders Video Interviews. )
    • Ping you a note about upcoming FREE educational webinars on GDPR and Cybersecurity.
    • Inform you of any upcoming Data Breach Response or Cyber Incident Response training.  
  • Using the information from this page we will NOT sell or market to you any of our consultancy or trusted advisory services.  
  • In its purest interpretation, this act of us communicating with you is direct marketing and is processed on the basis of our legitimate interest and your engaging in our services. All marketing communication will include an unsubscribe button or other method of ending communication.