SOLARWINDS SUNBURST
SUNBURST
CAMPAIGN / BREACH
RUSSIA
Threat IntelligenceCampaignMay 16, 202515 min read

SolarWinds SUNBURST: Threat Intelligence Profile

SolarWinds supply chain compromise

Scroll

SolarWinds SUNBURST (also known as SUNBURST, Solorigate) is a campaign / breach active since 2020. SolarWinds supply chain compromise. Key characteristics include: supply chain attack via Orion update, 18K+ organizations affected, APT29/Cozy Bear attribution, SUNSPOT build implant.

Overview & Background

SolarWinds supply chain compromise. First identified in 2020, this threat is attributed to Russia (SVR) / APT29.

Threat Assessment

SolarWinds SUNBURST remains an active threat. Organizations should implement detection rules and monitor for indicators associated with this campaign / breach.

Technical Analysis

SolarWinds SUNBURST employs the following capabilities and techniques:

MITRE ATT&CK Mapping

TacticTechniqueUsage
Initial AccessT1566.001 Phishing AttachmentCommon delivery vector
ExecutionT1204.002 Malicious FileUser-triggered execution
PersistenceT1547.001 Registry Run KeysAutostart persistence
Defense EvasionT1027 Obfuscated FilesPayload obfuscation
C2T1071.001 Web ProtocolsHTTP/HTTPS C2

Detection & Defense

Defend Against SolarWinds SUNBURST

Mjolnir Security provides detection and response capabilities against SolarWinds SUNBURST and similar threats.

Threat DetectionIncident ResponseThreat HuntingMDR ServicesThreat Intelligence
  • Proactive Threat Hunting Hunt for SolarWinds SUNBURST indicators and TTPs within your environment.
  • Threat Intelligence Monitor SolarWinds SUNBURST campaigns and infrastructure changes.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: May 16, 2025