A suspected Russian intelligence operation compromised SolarWinds' Orion software build process and pushed trojanized updates containing the SUNBURST backdoor to customers beginning in 2020, giving attackers a stealthy foothold inside government and private-sector networks. U.S. agencies including Treasury, Commerce, Homeland Security, State, and parts of the Pentagon were drawn into the response, while investigators and public reporting said roughly 18,000 customers received the malicious update and a smaller set suffered follow-on intrusions. FireEye's discovery of its own breach helped expose the campaign, and later technical reporting tied the operation to second-stage malware including TEARDROP and Raindrop, with officials assessing the activity as a long-running espionage effort rather than destructive sabotage.
The victim list expanded beyond federal agencies to major enterprises and institutions including Cisco, Intel, Nvidia, VMware, Deloitte, Belkin, Kent State University, and Malwarebytes, though several said they found the tainted software without evidence of deeper compromise. Subsequent reporting and congressional scrutiny also focused on how the attackers abused Microsoft cloud and identity weaknesses to impersonate users and access email, with lawmakers pressing Microsoft over claims that internal warnings had been missed before the SolarWinds campaign. SolarWinds' CEO later apologized for blaming an intern for a weak password issue, and said the intrusion may have begun as early as 2019, underscoring how long the attackers may have operated undetected and how difficult remediation became for affected organizations and critical infrastructure operators.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
54 events from the most recent confirmed update back to the earliest known activity.
The U.S. Securities and Exchange Commission dropped its civil fraud case against SolarWinds, marking a significant legal development in the aftermath of the Sunburst breach. This was separate from earlier shareholder litigation and changed the regulatory posture toward the company.
At a House Homeland Security Committee hearing, lawmakers pressed Microsoft President Brad Smith over reports that the company ignored internal warnings about a flaw later exploited by Russian hackers in the SolarWinds campaign. Smith said Microsoft accepted responsibility for broader security failings and was changing internal incentives to prioritize cybersecurity.
Mandiant released technical analysis describing how the SolarWinds supply-chain compromise used the SUNBURST backdoor and evasive post-compromise techniques. The publication consolidated forensic understanding of the campaign years after the initial disclosures.
The U.S. Department of Justice published a formal statement about the intrusion into its Microsoft O365 email environment, providing a later official update on the SolarWinds-linked compromise. The statement marked a renewed departmental response months after DOJ first disclosed that thousands of employee email accounts had been accessed.
Microsoft disclosed that the Russia-linked Nobelium group targeted and compromised customer support and reseller organizations, including a Microsoft customer support agent, to gain access to downstream customers. The company said the activity affected a small number of customers but showed the SolarWinds-linked actors were pursuing new supply-chain and trusted-access routes.
SolarWinds CEO Sudhakar Ramakrishna apologized for earlier remarks that had blamed an intern for a weak password issue. He also said the attack may have begun much earlier than first understood, possibly in January 2019.
CISA released detailed guidance for remediating networks affected by the SolarWinds compromise and related Active Directory and Microsoft 365 abuse. The document outlined steps for evicting attackers, rebuilding trust in identity systems, and recovering from federated authentication compromise.
The Biden administration formally blamed Russia's Foreign Intelligence Service (SVR), including its APT29/Cozy Bear unit, for the SolarWinds supply-chain espionage campaign. At the same time, the U.S. Treasury sanctioned six Russian technology firms for supporting Russian intelligence cyber operations, marking a major official response to the intrusion.
Canada publicly condemned the SolarWinds cyber-espionage campaign, assessed that APT29/Cozy Bear almost certainly operates as part of Russia's SVR, and said the malicious Orion updates had compromised more than 100 Canadian entities. Officials added that no known Canadian entities had been selected for follow-on exploitation at that time, while warning the investigation was ongoing.
AP reported that the SolarWinds espionage campaign gave attackers access to emails belonging to senior Department of Homeland Security officials. The disclosure added new detail about the extent of compromise inside DHS beyond earlier reports that the department had been affected.
Reporting said four cybersecurity vendors disclosed incidents connected to the SolarWinds espionage campaign, expanding the known list of affected security-sector organizations beyond previously reported cases. This marked a further broadening of the campaign's victim scope in the private sector.
Microsoft published a technical deep dive describing how SUNBURST infections led to second-stage payloads including TEARDROP and RAINDROP. The disclosure expanded public understanding of attacker tradecraft used after initial access.
Malwarebytes disclosed that it had been compromised by the same threat actors behind the SolarWinds campaign. The case showed the operation extended beyond government agencies into the cybersecurity sector.
Mimecast said a sophisticated threat actor compromised a certificate used by several of its products to authenticate to Microsoft 365 Exchange Web Services. The company said about 10% of customers used the affected connection, a low single-digit number of customer tenants showed signs of targeting, and Microsoft planned to block the certificate on 2021-01-18 while Mimecast advised customers to re-establish the connection with a new certificate.
CrowdStrike published analysis of SUNSPOT, the malware used to infiltrate SolarWinds' Orion build environment and swap malicious source code during active builds to insert the SUNBURST backdoor while evading detection. The report also described SolarWinds' timeline for the intrusion, including attacker access in September 2019, SUNBURST deployment on 2020-02-20, and removal on 2020-06-04.
Securelist published technical analysis of SUNBURST's DNS request patterns, explaining how the malware encoded host information and how defenders could use DNS artifacts to investigate possible compromise. The write-up added public technical detail to defender understanding of the SolarWinds backdoor's network behavior.
Kaspersky reported that historical malware analysis found multiple code-level similarities between the SUNBURST backdoor and Kazuar malware associated with the Russian-linked Turla group, including shared hashing, victim ID generation, and sleep-timer logic. Researchers said the overlaps strengthened the case for Russian intelligence involvement but did not conclusively prove Turla or the FSB directly carried out the SolarWinds intrusion.
SolarWinds hired former CISA director Chris Krebs and former Facebook security chief Alex Stamos to help respond to the fallout from the Sunburst supply-chain compromise. The move marked a notable company response aimed at strengthening incident handling and rebuilding trust after the hack.
The Administrative Office of the U.S. Courts disclosed that judiciary systems were compromised in the SolarWinds campaign, raising concerns that sealed and other non-public federal court filings in CM/ECF may have been exposed. The agency began a security audit with DHS and ordered highly sensitive documents to be filed and stored offline rather than uploaded to the court records system.
Reporting said investigators were examining whether a JetBrains TeamCity server used by SolarWinds may have played a role in the initial compromise behind the Sunburst campaign, although the access method remained unclear. JetBrains said neither SolarWinds nor any government agency had contacted the company about any role TeamCity may have played.
The U.S. Department of Justice disclosed that attackers tied to the SolarWinds campaign accessed about 3% of Office 365 inboxes, affecting more than 3,000 email accounts. DOJ said it detected the activity on December 24, 2020, linked it to the broader SolarWinds intrusion, blocked the access method, and found no indication that classified systems were affected.
SolarWinds was sued by shareholders in Texas seeking class-action status, alleging the company and executives misled investors about its cybersecurity posture and failed to disclose serious security weaknesses before the Sunburst compromise became public. The complaint named president Kevin Thompson and CFO Barton Kalsu and argued that the breach revelations caused investor losses after previously inflating the company’s share price.
ODNI, FBI, NSA, and CISA issued a joint statement assessing that a likely Russian actor was responsible for the espionage campaign. They said fewer than 10 federal agencies had been confirmed breached at that point and described the operation as focused on intelligence collection.
Microsoft disclosed that attackers tied to the SolarWinds espionage campaign accessed its internal network through a compromised employee account and were able to view some source code. The company said it found no evidence the intruders altered code or accessed production services, customer data, or email accounts.
CrowdStrike said Microsoft notified it of an attempted intrusion by the hackers behind the SolarWinds campaign. CrowdStrike reported that the attackers targeted the company's Microsoft reseller account but said it found no evidence the attempt led to a breach of its systems or customers.
The Washington Post reported that Russian government hackers compromised Microsoft cloud customers through a Microsoft corporate partner that provided cloud-access services. The intrusions reportedly led to the theft of emails from at least one private-sector company, revealing a trusted third-party access vector within the broader SolarWinds espionage campaign.
The Canadian Centre for Cyber Security warned Canadian SolarWinds Orion users to check their systems for signs of compromise following the supply-chain attack. It said Canadian government agencies and other organizations in Canada and abroad might be affected and that it was working to identify impacted systems and notify owners.
Senators Bob Menendez and Richard Blumenthal called on the State Department and Department of Veterans Affairs to brief lawmakers on their exposure to the SolarWinds compromise. The VA said it had seen no signs of exploitation and took SolarWinds offline as a precaution.
North American Electric Reliability Corporation warned utilities that the SolarWinds backdoor could threaten bulk power system reliability and asked organizations to report their exposure by Jan. 5. It also requested forensic indicators such as domains, IP addresses, and other compromise data where available.
Reporting identified organizations that had downloaded the trojanized Orion software, including Cisco, Intel, Nvidia, VMware, Deloitte, Belkin, the California Department of State Hospitals, and Kent State University. Several said they found the infected software but had not seen evidence of follow-on attacker activity.
Attorney General William Barr said it 'certainly appears' Russia was responsible for the SolarWinds cyberattack, aligning with Secretary of State Mike Pompeo and contradicting President Trump's suggestion that China might be to blame. The statement added another senior U.S. official to the public attribution of the campaign to Russia.
President Donald Trump minimized the severity of the intrusion and suggested China might be responsible, contradicting Pompeo, lawmakers, and many outside experts. His remarks highlighted a split in public messaging from the administration.
Secretary of State Mike Pompeo publicly said Russia was 'pretty clearly' responsible for the SolarWinds cyberattack. His statement marked one of the highest-level public attributions by the U.S. government.
The UK's National Cyber Security Centre said it was leading efforts with government and industry to assess the impact of the SolarWinds espionage campaign. Microsoft also said it had notified at least one UK customer that it had been compromised in connection with the operation.
The NSA published a security advisory describing how attackers can pivot from on-premises compromise into cloud environments by stealing SAML signing material to forge authentication tokens and by abusing global administrator access to create persistent cloud credentials. The agency also released mitigations, and reporting said the techniques matched activity observed in the SolarWinds campaign by FireEye, Microsoft, and CISA.
U.S. officials disclosed that the Department of Energy was affected by the SolarWinds espionage campaign. The National Nuclear Security Administration said the intrusion appeared limited to business networks and that there was no indication classified or weapons-related systems were impacted.
Microsoft President Brad Smith said that while about 18,000 organizations received the backdoored SolarWinds Orion update, only a very small subset—roughly 40, or about 0.2%—were chosen for second-stage exploitation. He said the selected targets were concentrated in technology companies, government agencies, and think tanks or NGOs, with about 80% located in the United States.
Members of Congress escalated public pressure over the incident, with senior lawmakers describing the campaign as a major national security breach and demanding stronger government action. The comments reflected growing concern over the scale and implications of the espionage operation.
Microsoft announced that Microsoft Defender Antivirus would start forcibly blocking and quarantining known malicious SolarWinds Orion binaries tied to the SUNBURST/Solorigate supply-chain compromise. The company said Orion versions 2019.4 through 2020.2.1 should be treated as compromised and advised customers to remove the software and investigate affected systems.
Reporting revealed that a SolarWinds FTP password had previously been exposed in plaintext on GitHub, prompting scrutiny of the company's security practices. The report did not establish that this leak caused the supply-chain compromise.
Microsoft, FireEye, and GoDaddy took control of the SUNBURST command-and-control domain avsvmcloud[.]com and redirected it to a Microsoft-owned IP range that caused the malware to disable itself. The action neutralized beaconing SUNBURST infections and helped defenders identify additional victims, though it did not remove any second-stage malware or other persistence already deployed.
Follow-on reporting said the SolarWinds espionage campaign also affected the U.S. Departments of Homeland Security, State, and Defense, expanding the known scope beyond Treasury and Commerce. The reports indicated attackers had monitored some compromised networks since March 2020 and were still active as recently as mid-December.
By mid-December, multiple officials and news outlets were publicly attributing the operation to suspected Russian government-backed hackers, often linking it to APT29/Cozy Bear or the SVR. Russia denied involvement.
Researchers reported that SolarWinds was still making a compromised Orion installer available for download on its website on December 14, 2020, even after public disclosure of the supply-chain attack. They said the package still contained the malicious DLL and that the signing certificate had not yet been revoked, indicating remediation was still incomplete.
U.S. cybersecurity officials warned that the SolarWinds incident posed a grave risk to federal, state, and local governments. The administration formed a cyber coordination effort involving CISA, the FBI, and ODNI to manage the response.
SolarWinds said in SEC-related disclosures that roughly 18,000 customers may have installed software containing the backdoor. The figure became the baseline estimate for the scale of exposure across public and private sectors.
As the campaign became public, Microsoft and SolarWinds released guidance and countermeasures to help customers detect and respond to the compromise. Federal investigators and law enforcement also began examining the incident.
News reports disclosed that the U.S. Treasury Department and Commerce Department were compromised in a sophisticated espionage operation tied to SolarWinds. Officials said attackers had monitored emails for months, and the revelations prompted an emergency National Security Council meeting.
After customers installed the trojanized Orion updates, the SUNBURST backdoor enabled stealthy access into victim environments for months. Investigators later found the campaign affected U.S. agencies and private organizations, with second-stage malware including TEARDROP and RAINDROP used in selected intrusions.
FireEye announced that it had been hacked by a highly sophisticated nation-state actor and that the attackers stole some of its red-team tools. The disclosure brought major public attention to the intrusion and preceded the broader revelation of the SolarWinds supply-chain campaign.
FireEye discovered it had been breached and its investigation helped expose the broader SolarWinds supply-chain campaign. This discovery triggered wider incident response and victim hunting across government and industry.
Attackers inserted malicious code into SolarWinds Orion software updates that were delivered to customers beginning in March 2020. SolarWinds later said about 18,000 customers received the compromised updates.
SolarWinds CEO later said the intrusion may have started in January 2019, indicating the attackers had access to the company well before the malicious Orion updates were distributed. He also apologized for earlier comments that had blamed an intern.
According to later reporting and congressional questioning, Microsoft engineer Andrew Harris began warning internally in 2017 about a security flaw that could allow attackers to impersonate legitimate users and access cloud data. The issue was reportedly not fully addressed and was later linked to the SolarWinds espionage campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
bankinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcetrustedsec.com
Open sourcecybersecuritydive.com
Open sourcecyberscoop.com
Open sourcecbc.ca
Open sourcewashingtonpost.com
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.