EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/supply-chain-attack/solarwinds-sunburst-attack
190/430

File EL-0241CriticalResolvedSupply Chain Attack / Nation-State Espionage

SolarWinds SUNBURST Supply Chain Attack

Also filed as SolarWinds Orion Compromise · SUNBURST Backdoor · APT29 SolarWinds Attack

The SolarWinds SUNBURST attack was a highly sophisticated supply chain compromise targeting the Orion network management platform. By injecting malicious code into a legitimate software update, the attackers gained access to thousands of high-value government and corporate networks. This incident represented a major escalation in nation-state cyber espionage, allowing prolonged, undetected surveillance.

  • #solarwinds
  • #sunburst
  • #apt29
  • #supply-chain-attack
  • #orion-platform
  • #russia
  • #espionage
Notoriety10/10
Event
13 Dec 2020
Disclosed
13 Dec 2020
Target
SolarWinds
Actor
Cozy Bear
Scale
Unknown (Estimated to be massive, involving years of communications)
Status
Resolved

01Summary

The attack began with the compromise of the SolarWinds Orion platform, a widely used network monitoring tool. The threat actors, attributed to APT29 (Cozy Bear), inserted a backdoor named SUNBURST into a legitimate software update package. When customers downloaded and installed this poisoned update, the malicious code was executed, establishing a persistent foothold within the victim's network. From this initial access, the attackers moved laterally, escalating privileges, and exfiltrating sensitive data, including emails, source code, and classified documents. The compromise was highly effective because it leveraged a trusted supply chain vector, bypassing traditional perimeter defenses and allowing the actors to operate for months undetected across multiple critical sectors, including US federal agencies and major technology firms.

02Background

SolarWinds Orion is a critical piece of infrastructure used by thousands of organizations globally for network monitoring and management. The inherent trust placed in such widely adopted enterprise software made it an ideal target for nation-state actors seeking deep, persistent access. This attack capitalized on the trust relationship between the vendor and its high-profile government and corporate clients.

03Key revelations

  1. 01The attackers gained deep, persistent access to multiple US federal agencies, including the Department of State and Treasury.
  2. 02The compromise demonstrated the vulnerability of widely trusted, critical infrastructure software to nation-state actors.
  3. 03The operation allowed the exfiltration of highly sensitive diplomatic cables, corporate intellectual property, and classified government documents.

04Technical analysis

The attack utilized a multi-stage kill chain. Initial access was achieved via the poisoned software update (supply chain compromise). The SUNBURST backdoor was designed to communicate with command-and-control (C2) infrastructure, often using legitimate-looking protocols (e.g., HTTPS). Once inside, the attackers employed techniques like credential harvesting and lateral movement to map the network and locate high-value data. The use of legitimate-looking updates made detection extremely difficult, as the malicious traffic blended with normal operational network activity.

Attack vector
Supply Chain Compromise (Poisoned Software Update)
Attack method
Espionage and Persistent Access
Initial access
Malicious Software Update (Supply Chain)
Lateral movement
Credential Harvesting and Exploitation
Persistence
Backdoor Installation (SUNBURST)
Exfiltration
Encrypted Communication over Standard Protocols (HTTPS)
Tool / malware
SUNBURST
Malware family
SUNBURST
Malware type
Backdoor/Spyware

Vulnerabilities exploited

  • Supply Chain Trust Model Exploitation

MITRE ATT&CK techniques

  • T1195.002
  • T1071.001
  • T1021.001

05Threat actor

Cozy Bear (APT29) is widely attributed to the Russian Foreign Intelligence Service (SVR). The group is known for its highly targeted, persistent espionage campaigns, focusing on stealing intellectual property and sensitive political information from Western governments and corporations.

Aliases

  • APT29
  • Fancy Bear
  • SVR

APT designations

  • APT29
  • Fancy Bear

MITRE groups

  • T1071.001
  • T1566.001
  • T1021.001

Attribution sources

  • Mandiant
  • FireEye
  • US Government Agencies

06Victims and impact

Additional victims

  • Department of Homeland Security
  • Department of Treasury
  • Department of Commerce
  • Department of State
  • National Nuclear Security Administration
  • Microsoft
  • Intel
  • Cisco

Countries affected

  • United States
  • Global

07Data exposed

Data types

  • Emails
  • Source Code
  • Financial Records
  • Classified Documents
  • Credentials

Notable documents

  • SolarWinds Orion Platform Source Code
  • Diplomatic Cables
  • Internal Corporate Communications

08Financial damage

Damage estimate is highly complex, involving years of intelligence loss and remediation costs.

09Timeline

  1. 2019-12-13Initial compromise of SolarWinds Orion platform begins.
  2. 2020-12-13The compromise is publicly disclosed by security firms and government agencies.

10Key figures

  • MandiantCybersecurity Firm · MandiantKey attribution and forensic analysis provider.

11On the record

The SolarWinds attack was a watershed moment, proving that the most trusted supply chains can be weaponized by nation-states.

Cybersecurity Expert, General assessment of the incident's impact.

12Reaction and fallout

Public reaction

The public reaction was one of alarm regarding the fragility of modern digital infrastructure and the increasing sophistication of state-sponsored cyber warfare. It spurred immediate, high-level discussions on supply chain security and zero-trust architectures.

Political impact

The incident led to increased scrutiny of foreign technology vendors and prompted US government agencies to accelerate the adoption of stricter cybersecurity standards and supply chain risk management frameworks.

Geopolitical consequences

It significantly heightened geopolitical tensions between the US and Russia, solidifying the narrative of Russia's use of cyber warfare as a primary tool of foreign policy and intelligence gathering.

13Legal

No specific criminal charges were publicly filed against the state actors, but the incident fueled subsequent legislative and regulatory efforts aimed at securing critical infrastructure.

Civil lawsuits

  • Class-action lawsuits against SolarWinds (related to breach disclosure and security failures)

14Aftermath

Policy changes

  • Increased focus on Software Bill of Materials (SBOM) requirements
  • Mandatory supply chain risk assessments for critical infrastructure

Regulatory changes

  • Enhanced federal guidelines for vetting foreign technology providers (e.g., CISA advisories)

Security improvements

  • Adoption of Zero Trust Network Architecture (ZTNA)
  • Mandatory multi-factor authentication (MFA) across government systems
  • Enhanced network segmentation and micro-segmentation

15Significance and legacy

Significance

The SolarWinds attack is considered a watershed moment in cybersecurity history. It fundamentally shifted the focus of cyber defense from perimeter security to supply chain integrity and zero-trust principles. It demonstrated that the most trusted, widely used software could be weaponized by nation-states for deep, long-term espionage.

Legacy

The incident permanently elevated supply chain risk management to a top-tier national security concern. It accelerated the global push for software transparency, leading to increased demand for verifiable software provenance and SBOMs.

16Disclosure and media

Authentication
Forensic Analysis and Code Review

Media partners

  • The New York Times
  • The Washington Post
  • BBC News

Publishing organisations

  • Mandiant
  • FireEye

17Related files

Related events

  • Colonial Pipeline Ransomware Attack

Inspired by

  • copenhagen-hack

Went on to inspire

  • multiple-ransomware-campaigns

18Field notes

  1. 01The attackers used a technique called 'living off the land,' meaning they used native tools already present on the victim's system to avoid detection.
  2. 02The attack was so sophisticated that it required months of forensic analysis by multiple private and government entities to fully map the scope of the breach.

19Resolution

The immediate threat was mitigated through forensic analysis, patching, and the implementation of enhanced network monitoring and segmentation across affected organizations.

20Sources

Official documents

  • CISA Advisory on SolarWinds Compromise
  • Mandiant Threat Report on APT29

References

  1. [1]Mandiant Threat Report
  2. [2]The New York Times Investigative Reporting
  3. [3]CISA Alerts
Fact sheetEL-0241

Dates

Event
13 Dec 2020
Started
13 Dec 2019
Ended
13 Dec 2020
Discovered
13 Dec 2020
Disclosed
13 Dec 2020
Ongoing
No

Target

Organisation
SolarWinds Corporation
Type
Technology Company
Sector
Network Management/IT Infrastructure
Country
United States
Gov. level
Corporation

Actor

Name
Cozy Bear
Type
Nation-State Actor
Nationality
Russian
Nation-state
Russia
Affiliation
Foreign Intelligence Service (SVR)
Motivation
Espionage and intelligence gathering against US government and critical infrastructure.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Unknown (Estimated to be massive, involving years of communications)
Sensitivity
Top Secret
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.