SUPERNOVA is a .NET C# in-memory web shell associated with SolarWinds Orion servers during the 2020 SolarWinds incident. It was observed as a trojanized, unsigned replacement of the legitimate SolarWinds Orion web application DLL App_Web_logoimagehandler.ashx.b6031896.dll, masquerading as a legitimate SolarWinds web service handler. The implant modifies ProcessRequest() and adds a DynamicRun() method that accepts attacker-supplied HTTP parameters, compiles supplied C# source code in memory via CSharpCodeProvider with GenerateInMemory enabled, instantiates a specified class, invokes a specified method, and returns output in the HTTP response. Reported parameters used for execution are codes, clazz, method, and args, and malicious responses may use Content-Type text/plain. SUPERNOVA enabled attackers to remotely send, compile, and execute C# code on compromised machines while minimizing on-disk artifacts and avoiding cmd.exe or PowerShell. It was installed via exploitation of the SolarWinds Orion API authentication bypass vulnerability CVE-2020-10148, which could allow authentication bypass and API command execution leading to compromise of the Orion application. The malware specifically targeted exposed SolarWinds Orion servers and was tracked separately from SUNBURST; multiple reports assessed it was likely associated with a different, less sophisticated actor because the binary was unsigned and did not match other SUNBURST tradecraft. Detection opportunities mentioned in the content include suspicious HTTP requests to logoimagehandler.ashx with the execution parameters, file or image load events involving logoimagehandler.ashx DLLs, and child processes CSC.exe and CVTRES.exe spawned during in-memory compilation. Known indicators directly cited include the filename pattern app_web_logoimagehandler.ashx.<8 alphanumeric chars>.dll and hashes for a trojanized DLL sample: SHA-256 c15abaf51e78ca56c0376522d699c978217bf041a3bd3c71d09193efa5717c71, SHA-1 75af292f34789a1c782ea36c7127bf6106f595e8, and MD5 56ceb6d0011d87b6e4d7023d7ef85676. SolarWinds stated remediation for affected Orion versions aligned with the broader Orion fixes, including updates such as 2020.2.1 HF2 and 2019.4 HF6.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Additionally, the SolarWinds Orion 0-day vulnerability which allowed for the Supernova Webshell to be installed is being tracked as CVE-2020-10148. | Additionally, the SolarWinds Orion 0-day vulnerability which allowed for the Supernova Webshell to be installed is being tracked as CVE-2020-10148. This vulnerability could enable an attacker to bypass authentication and allow for API command execution, which may lead to a compromise of the Orion application.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Investigations into the SolarWinds attack are now trying to determine whether the company was also targeted by a second, unrelated threat actor, that apparently may have leveraged a zero-day vulnerability affecting SolarWinds products and a piece of malware named Supernova.
"The parameters required for webshell remote code execution include the C# code intended to be compiled and executed by the .NET C# compiler..."
This additional malware, dubbed SuperNova, was deployed as a DLL file that allowed attackers to remotely send, compile, and execute C# code on compromised machines.
"...leveraged the Chrome vulnerability, CVE-2022-0609, in combination with a Drive-by Compromise website." / "...has exploited client software vulnerabilities for execution..." / "...has used multiple software exploits for common client software...to gain code execution."
Boot or logon initialization scripts, scheduled tasks, valid accounts, manipulating accounts, creating accounts, server software component, create/modify system process, event triggered execution, boot or logon autostart execution, hijack execution flow (MITRE ATT&CK: T1037, T1053, T1078, T1136, T1505, T1543, T1546, T1547, T1574)
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
"UNC3886 has exploited CVE-2023-34048 to enable command execution on vCenter servers..." / "VersaMem was installed through exploitation of CVE-2024-39717 in Versa Director servers." / "SUPERNOVA was installed via exploitation of a SolarWinds Orion API authentication bypass vulnerability (CVE-2020-10148)."
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Their toolkit includes ... SUNSPOT, SUPERNOVA, TEARDROP, TrailBlazer...
A trojanized SolarWinds Orion .NET DLL webshell that adds a DynamicRun() method to compile and execute attacker-supplied C# in-memory via CSharpCodeProvider, enabling arbitrary .NET payload execution without writing assemblies to disk.
DLL-based malware delivered via trojanized Orion builds that enabled remote submission, compilation, and execution of C# code on infected systems.
Backdoor malware referenced in the context of the SolarWinds incident; not analyzed in depth in this content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.