SolarWinds Orion
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Canada joins the United States and international partners in voicing our concerns related to a Russian cyber-espionage campaign that exploited the SolarWinds Orion platform.
The SVR achieved this by gaining access to the internal network of Texas-based software maker SolarWinds and inserting malware in a version of the Orion IT monitoring application. SolarWinds customers downloaded and installed the update, along with the SVR's malware, which allowed Russian operatives to gain a foothold in high-value targets...
Techniques & procedures
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
2 techniquesA federal payroll agency was targeted by suspected Chinese hackers who exploited a flaw within SolarWinds software, Reuters reported Tuesday...
Microsoft says the hackers operating on behalf of an external nation state compromised SolarWinds’ Orion monitoring and management software giving attackers a foothold in target networks.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious code inserted into trojanized SolarWinds Orion software updates to provide covert footholds in victim environments and enable follow-on compromise of internal and cloud systems for espionage.
Compromised SolarWinds Orion software updates were used to install malware on victim networks as part of a large-scale cyber-espionage supply-chain campaign.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.