Mandiant reported that attackers used the SUNBURST backdoor in the SolarWinds supply chain compromise to gain covert access to victim environments and conduct highly evasive follow-on operations. The activity stemmed from trojanized SolarWinds Orion software updates, which allowed the threat actor to establish an initial foothold through trusted software and then selectively expand access inside targeted networks.
The intrusion set was notable for stealth and operational discipline, with attackers using the compromised Orion platform to blend into normal administrative activity and reduce the chance of detection. The case underscores the long-term impact of software supply chain compromises, where a single trusted update mechanism can provide broad downstream access and enable persistent espionage across multiple organizations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
SentinelLabs published technical analysis of the SUNBURST backdoor, detailing its 12-14 day execution delay, blacklist-based checks for security tools and drivers, registry changes to disable defenses, and WMI-based driver enumeration. The report also shared hunting indicators including a weaponized OrionImprovementBusinessLayer class, a named pipe, the Win32_SystemDriver query, and traffic to avsvmcloud[.]com subdomains.
CISA released Malware Analysis Report MAR-10320115-1.v1 covering TEARDROP, a malware family associated with the SolarWinds intrusion. The report added technical detail and indicators to support defender detection and analysis of follow-on malware used after the initial compromise.
CISA published alert AA21-008A with guidance for detecting threat activity in Microsoft cloud environments following compromise activity associated with the SolarWinds campaign. The alert expanded official response guidance beyond the initial supply-chain compromise to downstream cloud-focused post-exploitation detection.
CrowdStrike revealed SUNSPOT, a malware implant deployed in SolarWinds' development environment to replace legitimate Orion source code with malicious code that inserted the SUNBURST backdoor into builds. The disclosure added new technical detail about how the supply-chain compromise was carried out and highlighted the attackers' operational security measures to avoid detection.
CISA published an official page on the SolarWinds supply chain compromise, documenting the incident and providing government guidance and response information. This marks an earlier public U.S. government advisory related to the SUNBURST campaign.
Microsoft published a Microsoft 365 Defender hunting query focused on detecting Solorigate-related behavior involving launching cmd.exe with echo. The release provided defenders with campaign-specific detection guidance during the early public response to the SolarWinds compromise.
Security researchers and industry partners seized control of avsvmcloud[.]com, a command-and-control domain used by the SUNBURST malware in the SolarWinds compromise, and repurposed it as a killswitch. FireEye said the action could cause some new and existing SUNBURST infections to terminate, though it would not remove attackers that had already established other persistence.
Microsoft updated its attribution for the SolarWinds supply-chain compromise, renaming the actor from the malware-centric label 'Solorigate' to NOBELIUM and linking it to the SUNBURST backdoor, TEARDROP malware, and related activity. The company also said it had released detections on December 13 and would begin blocking known malicious SolarWinds binaries with Microsoft Defender Antivirus on December 16 while urging customers to treat affected Orion systems as compromised.
Symantec published a threat-intelligence blog on the SUNBURST supply-chain attack targeting SolarWinds users. The post marks an early public security-industry analysis of the campaign shortly after its disclosure.
Mandiant published a blog post analyzing how an evasive attacker leveraged the SolarWinds supply chain compromise using the SUNBURST backdoor. No earlier event details are provided in the reference content, so the publication itself is the only extractable timeline event.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
otx.alienvault.com
Open sourceotx.alienvault.com
Open sourcemandiant.com
Open sourcesentinelone.com
Open sourcegithub.com
Open sourcekrebsonsecurity.com
Open sourcemicrosoft.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.