Analysis of the SolarWinds SUNBURST backdoor showed that DNS traffic to avsvmcloud.com was used not just for beaconing but as a bidirectional command-and-control channel that exfiltrated victim information from trojanized Orion deployments. Researchers found the malware encoded internal hostnames, Active Directory domain names, victim identifiers, and the status of some installed endpoint security products into DNS subdomains, with longer hostnames split across multiple queries and later reassembled. Public passive DNS analysis linked the campaign to victims including municipal and private-sector organizations, and recovered telemetry indicating environments running products such as Windows Defender, ESET, CrowdStrike Falcon, Carbon Black, and FireEye.
Further research showed that SUNBURST operators used DNS responses to decide whether an infected host would keep beaconing, stop communicating, or advance to later targeting stages that led to CNAME redirection and HTTPS-based follow-on command-and-control. The campaign’s infrastructure also illustrated the value of monitoring strategically aged domains: avsvmcloud.com had been registered well before malicious traffic surged, and burst patterns in passive DNS later became a model for detecting similar APT, phishing, and cloaking infrastructure. Defensive reporting tied the backdoor to broader post-compromise activity including lateral movement, credential theft, and abuse of cloud identity systems such as Azure AD.

TTPs, infrastructure, and targeting history in one profile.
15 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks published research on detecting strategically aged domains and bursty DGA subdomains, citing SUNBURST as a motivating case and feeding resulting detections into DNS Security and Next-Generation Firewall protections.
SentinelOne published reverse-engineering analysis showing SUNBURST waits roughly 12 to 14 days, then checks for blacklisted processes, services, and drivers, disabling some security services via registry changes and exiting if certain tools are present. The report also noted SentinelMonitor.sys is hardcoded in the driver blacklist and provided hunting indicators including a named pipe, WMI driver query, and a weaponized OrionImprovementBusinessLayer class.
Palo Alto Networks said its detector was capturing around 26,000 strategically aged domains per day in September 2021, supporting broader detection of malicious infrastructure that suddenly shifted from dormant to highly active.
Palo Alto Networks reported that the Pegasus-related domains permalinking[.]com and opposedarrangement[.]net, registered in 2019, became active in July 2021 with high DGA-subdomain traffic and roughly 56 times more daily DNS traffic on activation.
Netresec published a detailed analysis of SUNBURST's targeting process, describing avsvmcloud.com DNS as a two-way command-and-control channel that exfiltrated AD domain and security product data and used DNS responses to stop beaconing or advance selected victims to Stage 2 and Stage 3.
Netresec published guidance on robust network-based indicators for determining whether SUNBURST operators actively targeted a SolarWinds Orion victim, distinguishing these from weaker signs that only show installation of a trojanized update. The article identified STAGE2-flagged avsvmcloud DNS queries, CNAME responses, and A-record resolutions into 18.130.0.0/16, 99.79.0.0/16, or 184.72.0.0/15 as stronger indicators, and noted historical DNS logs back to April 2020 were needed for reliable analysis.
Netresec published analysis showing SunburstDomainDecoder v1.7 could extract victim identifiers and endpoint security product status from SUNBURST DNS beacons to avsvmcloud.com, including aggregate observations across affected SolarWinds customers.
Cloudflare published analysis showing SUNBURST used two hostname encoding schemes, that long hostnames could be split across multiple DNS queries, and that multipart messages could be paired through XOR relationships in decoded headers.
Netresec published a blog post on reassembling victim domain fragments from SUNBURST DNS traffic, contributing analysis of how victim information could be reconstructed from the malware's DNS beacons.
QiAnXin Technology's RedDrip Team published discoveries about SUNBURST's random subdomains, including how queries combined a GUID-like value with encoded hostname data and Python tooling for decoding them.
Splunk published detection guidance describing the trojanized SolarWinds Orion DLL supply-chain compromise, noting risks including lateral movement, data theft, and Azure AD targeting via captured passwords or forged SAML tokens.
Netresec reported that SUNBURST DNS traffic from the City of Kingston, Ontario encoded both a victim GUID and Windows Defender status values, including running and stopped states, in June 2020.
Palo Alto Networks said high attack traffic to avsvmcloud[.]com began in March 2020, with passive DNS traffic increasing by about 165 times after the SolarWinds attack started.
Splunk, citing FireEye, said activity associated with the SUNBURST campaign dated back at least to spring 2020, when the trojanized SolarWinds Orion DLL was already being used to gain footholds in victim environments.
Palo Alto Networks reported that the SUNBURST command-and-control domain avsvmcloud[.]com was registered in 2018 and then remained largely dormant for about two years before later attack traffic surged.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 70 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
11 references tracked. Mallory keeps watching after this page renders.
unit42.paloaltonetworks.com
Open sourcelabs.sentinelone.com
Open sourcenetresec.com
Open sourcenetresec.com
Open sourceblog.cloudflare.com
Open sourcenetresec.com
Open sourcesplunk.com
Open sourcemp.weixin.qq.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.