CASE DOSSIER alleged

SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)

Docket: SEC CIK 0001739942 Court: U.S. District Court for the Southern District of New York Opened: 2020-12-13 Sector: Information Technology, Defense, Federal Government, Telecommunications

Key Facts

Status
ALLEGED
Legal disposition
Loss Amount
$200.0 million
Multi-hundred million dollar investigation and incident remediation costs across the Department of Homeland Security, Treasury, and Fortune 500 firms.
Techniques
5
Verified mappings
Defendants
0
Named in charges
  • Legal Status: ALLEGED in U.S. District Court for the Southern District of New York.
  • Primary Target Sector: Information Technology, Defense, Federal Government, Telecommunications.
  • Documented Financial Loss: $200.0 million.
  • 5 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Sophisticated software supply chain compromise by the Russian Foreign Intelligence Service (SVR), inserting the SUNBURST backdoor into updates of SolarWinds Orion software and compromising multiple federal agencies.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Russian Foreign Intelligence Service (SVR / APT29) operatives infiltrated SolarWinds internal software development environment and modified the automated build pipeline to inject the SUNBURST backdoor into legitimate Orion DLL source files.

Operational & Financial Fallout

Approximately 18,000 public and private organizations installed the poisoned software update, including the US Treasury, Department of Homeland Security, Department of Energy, and Microsoft. Attackers hand-selected high-value federal targets for second-stage espionage, monitoring internal email and cloud systems undetected for nine months.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: ALLEGED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Russian Foreign Intelligence Service (SVR / APT29) operatives infiltrated SolarWinds internal software development environment and modified the automated build pipeline to inject the SUNBURST backdoor into legitimate Orion DLL source files.

Adversary Kill Chain Flow

5 Documented Phases
1
Build Pipeline Infiltration Temporary Source Injection via MSBuild Worker
MITRE ATT&CK T1190 →

Operatives installed a customized implant (SUNSPOT) on SolarWinds build servers that monitored for MSBuild processes, dynamically substituting legitimate source files with the backdoored code seconds before compilation.

Artifacts & Tooling: SUNSPOT implant SolarWinds.Orion.Core.BusinessLayer.dll MSBuild injection
2
Code Signing & Distribution Legitimately Signed Commercial Software Update
MITRE ATT&CK T1588.002 →

The backdoored binary was compiled and digitally signed with SolarWinds authentic Symantec code-signing certificate, then distributed to thousands of global customers as a standard security release.

Artifacts & Tooling: Symantec digital certificate Orion update package
3
Evasion & Dormancy Two-Week Dormancy and Host Environment Inspection
MITRE ATT&CK T1027 →

Once installed on customer networks, the SUNBURST backdoor stayed completely inert for up to two weeks, verifying that no analysis tools or security agents were actively debugging the process before activating.

Artifacts & Tooling: SUNBURST sleep timer Security product blacklists
4
C2 Communication Dynamic DNS Generation Mimicking AWS Telemetry
MITRE ATT&CK T1071.004 →

SUNBURST encoded victim host details and domain names into DNS A-record queries destined for avsvmcloud[.]com, disguising command-and-control beacons as routine Amazon Web Services cloud traffic.

Artifacts & Tooling: avsvmcloud[.]com DNS tunneling DGA queries
5
Golden SAML & Cloud Compromise Active Directory Federation Token Forgery
MITRE ATT&CK T1558.003 →

For priority targets, operatives stole the Active Directory Federation Services (AD FS) token-signing private certificate, forging SAML tokens to access Microsoft 365 email and cloud environments without passwords.

Artifacts & Tooling: Golden SAML assertion AD FS token-signing key theft TEARDROP loader
Real-World Blast Radius & Operational Fallout

Approximately 18,000 public and private organizations installed the poisoned software update, including the US Treasury, Department of Homeland Security, Department of Energy, and Microsoft. Attackers hand-selected high-value federal targets for second-stage espionage, monitoring internal email and cloud systems undetected for nine months.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Implement hermetic, reproducible build pipelines with dual-signature code verification.
✓ Protect Active Directory Federation Services (AD FS) signing keys in Hardware Security Modules (HSMs).
✓ Continuously inspect DNS queries for high-entropy DGA subdomains and anomalous TXT/A-record patterns.
✓ Mandate zero-trust conditional access policies that verify device health regardless of valid SAML claims.

Procedural & Incident Timeline

2020-12-14 disclosure

SolarWinds files Form 8-K Item 8.01 disclosing cyber incident involving Orion software compromise.

2020-12-17 advisory

CISA issues Alert AA20-352A: Advanced Persistent Threat Compromise of Government Agencies.

2021-04-15 sanction

White House and Treasury formally attribute operation to Russian SVR and sanction associated IT contractors.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1190 Exploit Public-Facing Application
Initial Access
"Adversaries inserted malicious source code (SUNBURST) into legitimate SolarWinds Orion build pipelines, resulting in digitally signed malicious updates." CISA Advisory AA20-352A ¶ 8 reviewed
T1071.001 Web Protocols
Command and Control
"The backdoor communicated with adversary command and control servers via HTTP requests designed to mimic legitimate SolarWinds Orion communication protocols." CISA Advisory AA20-352A ¶ 14 reviewed
T1078 Valid Accounts
Defense Evasion
"Adversaries abused stolen SAML signing keys to forge authentication tokens and bypass multifactor authentication in victim Microsoft 365 environments." CISA Emergency Directive 21-01 reviewed
T1132 Data Encoding
Command and Control
"SUNBURST encoded stolen domain information into custom Base64-like strings disguised as GUID query parameters." CISA Advisory AA20-352A ¶ 16 reviewed
T1036 Masquerading
Defense Evasion
"The TEARDROP memory-only dropper masqueraded as legitimate Windows system services to maintain persistent memory presence." CISA Advisory AA20-352A ¶ 21 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, SolarWinds Orion Supply Chain Intrusion (APT29 / SVR), No. SEC CIK 0001739942 (U.S. District Court for the Southern District of New York 2020), https://cybercaselibrary.com/cases/solarwinds-orion-supply-chain-compromise/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/solarwinds-orion-supply-chain-compromise" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>