Educational & easy-to consume visual guides to understanding attacks & enhancing resilience
At Cyber Management Alliance, Incident Response is our passion. We study and analyse cyber-attacks to create informational visual timelines which can be easily read for educational purposes and to enhance cyber resilience.
For the SolarWinds cyber-attack, also known as the Solorigate attack, we have created a visual timeline and an accompanying detailed report. Download it now.
Don't forget to read our blog on the SolarWinds Supply Chain Attack.
Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.
The SolarWinds cyber attack, also known as Solorigate or the Sunburst attack, was a sophisticated supply chain attack publicly disclosed in December 2020. Suspected nation-state hackers compromised the build process of SolarWinds' Orion IT monitoring software and inserted a backdoor known as SUNBURST into legitimate, digitally signed software updates. Around 18,000 SolarWinds customers downloaded the trojanised Orion updates released between March and June 2020, although only a much smaller number were selected for active follow-on intrusion. Victims included multiple US federal agencies and major technology companies, making it one of the most significant cyber-espionage campaigns ever uncovered.
Investigators traced the earliest intrusion activity to January 2019, when the attackers carried out very early reconnaissance. They ran a trial run of their code injection from September 2019, injected the SUNBURST backdoor into the Orion source code in February 2020, and SolarWinds released the poisoned hotfix on 26 March 2020. The breach was not discovered until December 2020: FireEye disclosed its own breach on 8 December 2020, and SolarWinds publicly confirmed the supply chain compromise on 13 December 2020. The attackers therefore had access for close to two years before detection.
The attack was attributed to a nation-state group. In April 2021, the US government (NSA, FBI and CISA), together with the UK's NCSC, formally attributed the campaign to actors associated with Russia's Foreign Intelligence Service (SVR), also tracked as APT29, Cozy Bear and The Dukes. Before formal attribution, the threat actor was tracked under names including UNC2452 (by FireEye), Dark Halo (by Volexity) and SolarStorm (by Palo Alto Unit 42). Russia denied responsibility, and some early speculation pointed elsewhere, but the consensus of US and UK intelligence agencies pointed to Russian state-sponsored actors.
The attackers compromised SolarWinds' software build environment and used a tool called SUNSPOT to insert the SUNBURST backdoor into the source code of the Orion platform. The malicious code was then compiled, digitally signed with a valid SolarWinds certificate and distributed to customers through the company's normal, trusted software update process. Because the update appeared legitimate, organisations unknowingly installed the backdoor. After lying dormant for around two weeks, it could communicate with command-and-control infrastructure and, against selected high-value targets, deploy further malware such as TEARDROP and Cobalt Strike BEACON and escalate privileges within the network.
Several pieces of malware were linked to the campaign. SUNSPOT was used to inject the backdoor during the build process; SUNBURST (also called Solorigate) was the backdoor distributed through Orion updates; TEARDROP was a memory-only dropper used to deploy Cobalt Strike BEACON against high-value targets; and RAINDROP was a related loader found at some victims. A separate piece of malware called SUPERNOVA, linked to the vulnerability CVE-2020-10148, was found on some Orion servers but was assessed as not part of the original supply chain attack. Later related activity was tied to malware tracked as NOBELIUM and SUNSHUTTLE.
SolarWinds estimated that fewer than 18,000 customers installed the Orion updates containing the SUNBURST backdoor. However, only a much smaller subset was selected for active, follow-on intrusion. US officials later stated that around nine federal government agencies and roughly 100 private-sector companies were compromised through additional, targeted activity. Affected organisations spanned government, technology, consulting, telecoms and energy across North America, Europe, Asia and the Middle East.
Reported victims included numerous US federal agencies, among them the Departments of the Treasury, Commerce, State, Homeland Security, Justice and Energy (including the National Nuclear Security Administration), as well as NASA, the National Institutes of Health and the Federal Aviation Administration. Technology and security companies named in reporting included FireEye, Microsoft, Cisco, Intel, Nvidia, VMware, Deloitte and Mimecast. Victims were also confirmed in several other countries beyond the United States.
Because the campaign was an intelligence-gathering operation, the attackers focused on email and internal data at selected targets. Reporting indicated that they monitored internal email traffic at agencies such as the US Treasury and Commerce departments, accessed Office 365 mailboxes (the Department of Justice said around 3% of its mailboxes were potentially accessed), and in Microsoft's case viewed some internal source code repositories. The full scope of data taken was never completely disclosed, and several affected organisations said they found no evidence that production systems or customer data had been compromised.
No ransom was involved: this was an espionage campaign rather than a ransomware attack, so there was no ransom demand or payment, and no operational downtime was reported. SolarWinds disclosed around $3.5 million in expenses related to the incident in its early filings, covering investigation, remediation, legal and consulting costs, with further costs expected. The company also faced shareholder class-action lawsuits, a share price fall of roughly 17% to 22% after disclosure, and significant reputational damage.
The campaign came to light through the cybersecurity firm FireEye. On 8 December 2020, FireEye disclosed that it had been breached and that attackers had stolen its Red Team tools. While investigating its own compromise, FireEye traced the intrusion to a backdoor in SolarWinds' Orion software, reviewing around 50,000 lines of source code to confirm it, and then notified SolarWinds and law enforcement. SolarWinds publicly confirmed the supply chain compromise on 13 December 2020. Many analysts noted that the breach might have gone undetected for much longer had FireEye itself not been targeted.
SolarWinds released hotfix updates to replace the compromised component, engaged external cybersecurity specialists, and worked with FireEye, the FBI and the intelligence community. The US Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive 21-01 ordering federal agencies to disconnect affected Orion products, and a Cyber Unified Coordination Group was established to coordinate the government-wide response. Microsoft and industry partners sinkholed key attacker infrastructure, and in April 2021 the US imposed sanctions on Russia over the campaign.
The SolarWinds incident is a landmark example of supply chain risk: trusted, signed software updates became the delivery mechanism for a sophisticated backdoor that bypassed traditional defences. The key lessons are to scrutinise the security of software build pipelines and third-party vendors, to monitor for anomalous behaviour rather than relying solely on signatures, to apply network segmentation and least-privilege access, and to maintain tested incident response plans for stealthy, long-dwell intrusions. Cyber Management Alliance helps organisations build these capabilities through training, cyber crisis tabletop exercises and incident response planning.
We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.
Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.
A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.
Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.