CISA and multiple security firms reported intrusions in which attackers deployed the SUPERNOVA web shell and other backdoored components on SolarWinds Orion servers to steal credentials and maintain covert access. In one CISA-tracked case, the adversary accessed the victim through VPN using valid accounts and U.S.-based residential IP addresses, moved laterally with obfuscated PowerShell, reached the Orion server, dumped LSASS credentials, and exfiltrated stolen data through the organization’s web server. Investigators said log clearing prevented confirmation of whether initial access involved exploitation of CVE-2020-10148, and the attackers repeatedly deleted evidence to hinder response.
Separate incident reporting from Sophos described a similar Orion compromise in which attackers replaced OrionWeb.dll with a malicious unsigned version that harvested SolarWinds and LDAP credentials, created a hidden _system login protected by a dynamic daily password, and erased audit traces of that access. The actor also used a public-facing web shell, abused WMIC for remote execution, and attempted to dump Active Directory data, while post-compromise activity included masquerading tools such as procdump.exe and winrar.exe as wininit.exe. Splunk, Microsoft, and community defenders published detections focused on process creation telemetry such as Event ID 4688, suspicious Orion file changes, known SUPERNOVA hashes, and anomalous SolarWinds-related network and process activity.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Splunk published analysis of the CISA-reported SUPERNOVA intrusion, highlighting adversary use of U.S.-based residential IPs, obfuscated PowerShell, LSASS credential dumping, exfiltration through a web server, and renamed tools such as procdump.exe masquerading as wininit.exe or Splunklogger.exe. The post also provided Splunk and Sysmon hunting guidance tied to the incident's indicators and behaviors.
CISA issued analyst report AR21-112A describing an incident response engagement involving the SUPERNOVA web shell on a compromised SolarWinds Orion server. The report documented post-compromise activity including VPN access with valid accounts, credential dumping, exfiltration, and masquerading.
A GitHub gist published Microsoft Defender for Endpoint KQL detections for SolarWinds compromise activity, including known SUNBURST domains and hashes and the SUPERNOVA MD5 hash. The material focused on operational detection logic rather than incident reporting.
After Sophos disclosed the NTDS dumping and related intrusion activity, the customer reset affected credentials, initiated domain-wide password resets, isolated implicated hosts, blocked suspicious IPs, and rebuilt systems. These actions were taken to contain and remove the Orion backdoor and associated web shell access.
Sophos discovered an ASPX web shell named about.aspx on the public web server and found that the attacker had copied a malicious unsigned file into the SolarWinds Orion bin directory as OrionWeb.dll. Reverse engineering showed the DLL captured SolarWinds and LDAP credentials, enabled a hidden '_system' login, and deleted related audit evidence.
During the November 2020 intrusion, the attacker used w3wp.exe-launched commands, created backup.bat remotely, and ran ntdsutil with 'ifm create full' to dump the Active Directory database from a domain controller. Sophos assessed this as credential access and privilege escalation activity.
In November 2020, Sophos MTR detected suspicious WMIC activity in the customer's environment, indicating a new intrusion distinct from the earlier Ragnar Locker incident. The activity traced back to a public IIS web server and led to broader investigation.
Sophos said the U.S.-based ISP and telecommunications customer had previously suffered a Ragnar Locker ransomware attack, and Rapid Response determined the threat actor had been in the network for two months before deployment. This earlier incident preceded the later SolarWinds Orion backdoor intrusion.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 22 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
5 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourceus-cert.cisa.gov
Open sourcesplunk.com
Open sourcegist.github.com
Open sourcedocs.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.