SUPERNOVA is a .NET web shell and backdoor associated with compromises of the SolarWinds Orion platform during the broader 2020 SolarWinds incident. It masquerades as a legitimate SolarWinds web service component and was observed as a trojanized Orion DLL that exposed attacker-controlled functionality through the Orion web application stack. Unlike SUNBURST, which was distributed through the Orion software supply-chain compromise, SUPERNOVA has been widely assessed as a separate intrusion set and likely attributable to a different adversary.
The malware enables remote arbitrary code execution by accepting attacker-supplied C# source code, compiling it in memory, and executing the resulting assembly directly on the compromised server. This in-memory execution model reduces disk artifacts and supports stealthy post-compromise operations. SUPERNOVA has been described as a web shell planted in Orion code and as a malicious web service handler embedded in the SolarWinds HTTP API environment.
Observed intrusions involving SUPERNOVA included installation on SolarWinds Orion servers after adversaries gained access through other means, including valid-account VPN access and likely exploitation of CVE-2020-10148, an authentication bypass in the SolarWinds Orion API that could permit command execution as SYSTEM. In incident reporting, operators used the Orion server as a pivot point for credential harvesting, including LSASS dumping, followed by lateral movement, local staging, exfiltration, and log deletion. These downstream actions reflect how SUPERNOVA functioned as an execution and persistence foothold within enterprise environments rather than as the initial supply-chain implant itself.
SUPERNOVA is most closely associated with SolarWinds Orion deployments in enterprise and government networks. Its discovery during the SolarWinds crisis initially caused attribution confusion, but subsequent assessments consistently treated it as distinct from the SUNBURST campaign even though both affected the same product ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CISA believes the logs would have likely revealed the threat actor exploited CVE-2020-10148, an authentication bypass vulnerability in SolarWinds Orion Application Programming Interface (API) that allows a remote attacker to execute API commands. CISA believes the threat actor leveraged CVE-2020-10148 to bypass the authentication to the SolarWinds appliance and then used SolarWinds Orion API ExecuteExternalProgram() to run commands with the same privileges the SolarWinds appliance was running (in this case SYSTEM). | The threat actor then moved laterally to the entity’s SolarWinds Orion appliance and established persistence by using a PowerShell script to decode and install SUPERNOVA... The SUPERNOVA webshell allows a remote operator to dynamically inject C# source code into a web portal provided via the SolarWinds software suite.
the National Security Agency released an advisory earlier this month about CVE-2020-4006, a command injection vulnerability, stating that Russian state-sponsored actors were actively exploiting the vulnerability and suggesting US Government agencies patch immediately. This vulnerability exists in five VMware software products focused on identity and access management.
Trend Micro's Zero-Day Initiative (ZDI) provided technical analysis of recently patched vulnerabilities in the SolarWinds Orion Platform. CVE-2020-14005, one of these vulnerabilities, has been linked to the recent SUNBURST cyberattack on SolarWinds. These vulnerabilities, when combined, could allow an unauthenticated attacker to execute arbitrary code as Administrator on an affected system.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
As part of the observed campaigns, malware such as BazarLoader, Cobalt Strike, MiniDuke, “CosmicDuke”, Sunburst, SUPERNOVA, and more, were employed by APT29 attackers.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
...post-exploitation activity and filewrites occur within inetpub in-the-wild and are more indicative of web-facing exploitation with artifacts more similar to CVE-2019-8917.
the attacker can send arbitrary code to the infected device and execute it in the context of the user
established Persistence by using a PowerShell script (Command and Scripting Interpreter: PowerShell [T1059.001]) to decode and install SUPERNOVA
This additional malware, dubbed SuperNova, was deployed as a DLL file that allowed attackers to remotely send, compile, and execute C# code on compromised machines.
"...leveraged the Chrome vulnerability, CVE-2022-0609, in combination with a Drive-by Compromise website." / "...has exploited client software vulnerabilities for execution..." / "...has used multiple software exploits for common client software...to gain code execution."
Boot or logon initialization scripts, scheduled tasks, valid accounts, manipulating accounts, creating accounts, server software component, create/modify system process, event triggered execution, boot or logon autostart execution, hijack execution flow (MITRE ATT&CK: T1037, T1053, T1078, T1136, T1505, T1543, T1546, T1547, T1574)
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
"UNC3886 has exploited CVE-2023-34048 to enable command execution on vCenter servers..." / "VersaMem was installed through exploitation of CVE-2024-39717 in Versa Director servers." / "SUPERNOVA was installed via exploitation of a SolarWinds Orion API authentication bypass vulnerability (CVE-2020-10148)."
Once running, it inspects and responds to HTTP requests with appropriate HTTP query strings, cookies, and HTML form values. It can also execute web shell commands via a specific HTTP request format.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Their toolkit includes ... SUNSPOT, SUPERNOVA, TEARDROP, TrailBlazer...
A trojanized SolarWinds Orion .NET DLL webshell that adds a DynamicRun() method to compile and execute attacker-supplied C# in-memory via CSharpCodeProvider, enabling arbitrary .NET payload execution without writing assemblies to disk.
Mentioned only as another malware/tool used in campaigns attributed to APT29.
A malicious trojanized .NET library embedded in SolarWinds Orion that functions as a webshell/backdoor, accepts parameters from C2, dynamically compiles them into an in-memory .NET assembly via the DynamicRun method, and enables arbitrary code execution without leaving disk artifacts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.