SolarWinds refers to the 2020 supply-chain compromise in which Russian state-sponsored threat actors implanted malware into SolarWinds software updates after infiltrating the company’s build pipeline. The malicious code was inserted into digitally signed updates, allowing the operation to bypass internal security controls at victim organizations. U.S. officials linked the broader cyberespionage campaign to Russian intelligence operatives. The intrusion is described as a major cyberespionage campaign and a prominent example of software supply-chain compromise. Reported impact in the provided content includes 425 Fortune 500 companies and victims that unknowingly installed the compromised update. The content characterizes the operation as supply-chain malware delivered through trusted vendor software updates; no specific malware family name or technical indicators of compromise are provided in the source material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
And if they gain admin, network and ultimately system access, they can start launching attacks on critical infrastructure.
18,000 organizations were infected from March to June by malicious code that piggybacked on popular network-management software from an Austin, Texas, company called SolarWinds.
noting that the ransomware group appeared to have borrowed some techniques from the Russian intelligence agency that last year manipulated the software code sold by a company called SolarWinds that maintained broad access to government and corporate networks.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious backdoor inserted into SolarWinds Orion software updates, used for large-scale supply chain compromise and espionage.
Name used for a major supply-chain cyberespionage campaign linked by U.S. officials to Russian intelligence operatives.
Malware implanted into a SolarWinds software update as part of a supply-chain compromise affecting downstream victims.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.