{
  "id": "case-solarwinds-apt29",
  "slug": "solarwinds-orion-supply-chain-compromise",
  "title": "SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)",
  "summary": "Sophisticated software supply chain compromise by the Russian Foreign Intelligence Service (SVR), inserting the SUNBURST backdoor into updates of SolarWinds Orion software and compromising multiple federal agencies.",
  "case_number": "SEC CIK 0001739942",
  "court": "U.S. District Court for the Southern District of New York",
  "district": "S.D.N.Y.",
  "country": "United States",
  "opened_at": "2020-12-13",
  "status": "alleged",
  "victim_sector": "Information Technology, Defense, Federal Government, Telecommunications",
  "victim_country": "United States, United Kingdom, Canada, European Union",
  "loss_amount_usd": 200000000,
  "loss_amount_note": "Multi-hundred million dollar investigation and incident remediation costs across the Department of Homeland Security, Treasury, and Fortune 500 firms.",
  "first_seen_at": "2019-09-04T00:00:00Z",
  "last_updated_at": "2026-09-18T18:00:00Z",
  "actor_slug": "apt29",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Adversaries inserted malicious source code (SUNBURST) into legitimate SolarWinds Orion build pipelines, resulting in digitally signed malicious updates.",
      "evidence_locator": "CISA Advisory AA20-352A \u00b6 8",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA20-352A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1071.001",
      "evidence_excerpt": "The backdoor communicated with adversary command and control servers via HTTP requests designed to mimic legitimate SolarWinds Orion communication protocols.",
      "evidence_locator": "CISA Advisory AA20-352A \u00b6 14",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Technical Analysis",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a",
      "technique_name": "Web Protocols",
      "tactic": "Command and Control"
    },
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Adversaries abused stolen SAML signing keys to forge authentication tokens and bypass multifactor authentication in victim Microsoft 365 environments.",
      "evidence_locator": "CISA Emergency Directive 21-01",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Emergency Directive 21-01",
      "source_url": "https://www.cisa.gov/news-events/directives/ed-21-01-mitigate-solarwinds-orion-code-compromise",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1132",
      "evidence_excerpt": "SUNBURST encoded stolen domain information into custom Base64-like strings disguised as GUID query parameters.",
      "evidence_locator": "CISA Advisory AA20-352A \u00b6 16",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA20-352A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a",
      "technique_name": "Data Encoding",
      "tactic": "Command and Control"
    },
    {
      "technique_id": "T1036",
      "evidence_excerpt": "The TEARDROP memory-only dropper masqueraded as legitimate Windows system services to maintain persistent memory presence.",
      "evidence_locator": "CISA Advisory AA20-352A \u00b6 21",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA20-352A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a",
      "technique_name": "Masquerading",
      "tactic": "Defense Evasion"
    }
  ],
  "events": [
    {
      "event_type": "disclosure",
      "event_date": "2020-12-14",
      "description": "SolarWinds files Form 8-K Item 8.01 disclosing cyber incident involving Orion software compromise."
    },
    {
      "event_type": "advisory",
      "event_date": "2020-12-17",
      "description": "CISA issues Alert AA20-352A: Advanced Persistent Threat Compromise of Government Agencies."
    },
    {
      "event_type": "sanction",
      "event_date": "2021-04-15",
      "description": "White House and Treasury formally attribute operation to Russian SVR and sanction associated IT contractors."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Russian Foreign Intelligence Service (SVR / APT29) operatives infiltrated SolarWinds internal software development environment and modified the automated build pipeline to inject the SUNBURST backdoor into legitimate Orion DLL source files.",
    "blast_radius": "Approximately 18,000 public and private organizations installed the poisoned software update, including the US Treasury, Department of Homeland Security, Department of Energy, and Microsoft. Attackers hand-selected high-value federal targets for second-stage espionage, monitoring internal email and cloud systems undetected for nine months.",
    "kill_chain": [
      {
        "phase": "Build Pipeline Infiltration",
        "title": "Temporary Source Injection via MSBuild Worker",
        "description": "Operatives installed a customized implant (SUNSPOT) on SolarWinds build servers that monitored for MSBuild processes, dynamically substituting legitimate source files with the backdoored code seconds before compilation.",
        "technical_artifacts": [
          "SUNSPOT implant",
          "SolarWinds.Orion.Core.BusinessLayer.dll",
          "MSBuild injection"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Code Signing & Distribution",
        "title": "Legitimately Signed Commercial Software Update",
        "description": "The backdoored binary was compiled and digitally signed with SolarWinds authentic Symantec code-signing certificate, then distributed to thousands of global customers as a standard security release.",
        "technical_artifacts": [
          "Symantec digital certificate",
          "Orion update package"
        ],
        "mitre_technique_id": "T1588.002"
      },
      {
        "phase": "Evasion & Dormancy",
        "title": "Two-Week Dormancy and Host Environment Inspection",
        "description": "Once installed on customer networks, the SUNBURST backdoor stayed completely inert for up to two weeks, verifying that no analysis tools or security agents were actively debugging the process before activating.",
        "technical_artifacts": [
          "SUNBURST sleep timer",
          "Security product blacklists"
        ],
        "mitre_technique_id": "T1027"
      },
      {
        "phase": "C2 Communication",
        "title": "Dynamic DNS Generation Mimicking AWS Telemetry",
        "description": "SUNBURST encoded victim host details and domain names into DNS A-record queries destined for avsvmcloud[.]com, disguising command-and-control beacons as routine Amazon Web Services cloud traffic.",
        "technical_artifacts": [
          "avsvmcloud[.]com",
          "DNS tunneling",
          "DGA queries"
        ],
        "mitre_technique_id": "T1071.004"
      },
      {
        "phase": "Golden SAML & Cloud Compromise",
        "title": "Active Directory Federation Token Forgery",
        "description": "For priority targets, operatives stole the Active Directory Federation Services (AD FS) token-signing private certificate, forging SAML tokens to access Microsoft 365 email and cloud environments without passwords.",
        "technical_artifacts": [
          "Golden SAML assertion",
          "AD FS token-signing key theft",
          "TEARDROP loader"
        ],
        "mitre_technique_id": "T1558.003"
      }
    ],
    "defensive_takeaways": [
      "Implement hermetic, reproducible build pipelines with dual-signature code verification.",
      "Protect Active Directory Federation Services (AD FS) signing keys in Hardware Security Modules (HSMs).",
      "Continuously inspect DNS queries for high-entropy DGA subdomains and anomalous TXT/A-record patterns.",
      "Mandate zero-trust conditional access policies that verify device health regardless of valid SAML claims."
    ]
  }
}