The SolarWinds Compromise was a major supply-chain intrusion campaign publicly attributed to APT29, a Russian state-linked espionage actor also widely tracked as Cozy Bear and The Dukes. The operation is notable for combining trusted-relationship abuse with extensive post-compromise discovery in enterprise and cloud environments. Activity associated with the campaign included obtaining access through compromised accounts at cloud solution partners and using compromised Mimecast-issued certificates to authenticate to downstream customer systems. Observed tradecraft included account discovery and environment reconnaissance using native administrative tooling and PowerShell. APT29 operators used Active Directory cmdlets such as Get-ADUser and Get-ADGroupMember to enumerate domain accounts and group membership, and used Exchange administrative commands such as Get-WebServicesVirtualDirectory to gather Exchange virtual directory configuration information. These behaviors are consistent with a disciplined espionage workflow focused on mapping identity infrastructure, understanding victim environments, and enabling follow-on access and lateral operations through trusted enterprise services. The campaign is best characterized as a Russian state-aligned espionage operation rather than a ransomware or financially motivated intrusion set. Known attribution in the supplied facts centers on APT29/Cozy Bear.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign activity included obtaining configured Exchange virtual directory information.
Campaign in which operators used PowerShell Active Directory cmdlets to discover domain accounts and group membership.
Supply-chain/third-party compromise activity in which downstream access was achieved via cloud solution partner accounts and compromised Mimecast-issued certificates.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.