SUNSPOT is a Windows malware implant used in the SolarWinds supply-chain compromise to tamper with the SolarWinds Orion build environment and insert the SUNBURST backdoor into Orion software builds. Reporting in the provided content associates SUNSPOT with APT29, also tracked as UNC2452, Dark Halo, Nobelium, and by CrowdStrike as StellarParticle. The malware was dropped into the SolarWinds development environment, monitored the Orion build process, detected active MsBuild.exe executions for the Orion solution, and replaced a legitimate Orion source file with a backdoored version during compilation. After the build completed, it restored the original source file to reduce the chance of detection. The content states that SUNSPOT included multiple safeguards and operational security measures, including hardcoded MD5 checksum verification before replacing source code, encrypted blobs containing the malicious SUNBURST source code and target file paths protected with AES128-CBC, and cleanup of a temporary backup file named InventoryManager.bk. SUNSPOT used Windows API functions including MoveFileEx and NtQueryInformationProcess as part of the injection process, and modified its security token to add SeDebugPrivilege. Persistence was maintained via a scheduled task created to run at host boot. On disk, SUNSPOT was identified with the filename taskhostsvc.exe and created an encrypted log file at C:\Windows\Temp\vmware-vmdmp.log. Its role in the intrusion was specifically to compromise SolarWinds Orion builds so that trojanized, signed updates containing SUNBURST could be distributed to downstream victims, including governments and enterprises using Orion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A cited reference is 'sunspot malware technical analysis' in the context of APT29 and the SolarWinds intrusion.
In a blog post late last night, the infosec firm said the Orion-targeting malware, which it codenamed Sunspot, had "several safeguards" to ensure its deployment of compromised code into new Orion builds didn't trigger SolarWinds' suspicions.
Sunspot, as it was dubbed by CrowdStrike, was dropped by the attackers in the development environment of SolarWinds' Orion IT management software. After being executed, the malware would monitor and automatically injecting a Sunburst backdoor by replacing the company's legitimate source code with malicious code.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
APT29 employed a range of techniques for initial compromise, including spearphishing emails... Additionally, the group exploited vulnerabilities in public-facing infrastructure... APT29 also used supply chain compromise.
As part of the attack, the hackers gained access to the SolarWinds Orion build system and injected the sunburst backdoor into a legitimate DLL used by the SolarWinds Orion IT management software. This DLL was later automatically distributed to SolarWinds customers in a supply chain attack.
During the 3CX Supply Chain Attack, AppleJeus first compromised an "end-of-life" trading software application which was downloaded and executed inside the 3CX enterprise environment. The second compromise modified the Windows and macOS build environments used to distribute the 3CX software to their customer base.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
After being executed, the malware would monitor and automatically injecting a Sunburst backdoor by replacing the company's legitimate source code with malicious code... injected the sunburst backdoor into a legitimate DLL used by the SolarWinds Orion IT management software.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Akira has used legitimate names and locations for files to evade defenses.
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
After being executed, the malware would monitor and automatically injecting a Sunburst backdoor by replacing the company's legitimate source code with malicious code... injected the sunburst backdoor into a legitimate DLL used by the SolarWinds Orion IT management software.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Their toolkit includes ... SUNBURST, SUNSPOT, SUPERNOVA, TEARDROP...
APT29 malware used in the SolarWinds compromise, including for persistence via a scheduled task at host boot.
Malware used in the SolarWinds build environment compromise to tamper with the software build process and facilitate supply-chain backdooring.
Malware implanted in the SolarWinds build environment to monitor the build process and covertly replace legitimate source code with malicious code that inserted the Sunburst backdoor into Orion builds.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.