← Back to all campaigns
ActiveMITRE ATT&CK

SolarWinds Compromise

The SolarWinds Compromise was a sophisticated supply chain cyber operation conducted by APT29 that was discovered in mid-December 2020. APT29 used customized malware to inject malicious code into the SolarWinds Orion software build process that was later distributed through a normal software update; they also used password spraying, token theft, API abuse, spear phishing, and other supply chain attacks to compromise user accounts and leverage their associated access. Victims of this campaign included government, consulting, technology, telecom, and other organizations in North America, Europe, Asia, and the Middle East. This activity has been labled the StellarParticle campaign in industry reporting. Industry reporting also initially referred to the actors involved in this campaign as UNC2452, NOBELIUM, Dark Halo, and SolarStorm.

In April 2021, the US and UK governments attributed the SolarWinds Compromise to Russia's Foreign Intelligence Service (SVR); public statements included citations to APT29, Cozy Bear, and The Dukes. The US government assessed that of the approximately 18,000 affected public and private sector customers of Solar Winds’ Orion product, a much smaller number were compromised by follow-on APT29 activity on their systems.

First observedAug 1, 2019
Last observedJan 1, 2021
Attributed actors1
Source-backed events3
Attribution

Who has been linked to this activity

Each relationship retains its own confidence and source.

Source ReportedActive actor

APT29

APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research ...

mitre-attckReview source
Activity

Campaign timeline

Every date says what it measures so catalog dates are not confused with publication dates.

Cataloged
Attribution

APT29 attributed to this campaign

Attribution confidence: Source Reported.

Last observed
Campaign

SolarWinds Compromise last observed

The campaign source marks this as the latest known activity date.

MITRE ATT&CKSource
First observed
Campaign

SolarWinds Compromise first observed

The campaign source marks this as the beginning of the known activity window.

MITRE ATT&CKSource
About the context below

CVEs, techniques, malware, and indicators in the sections below are associated with an attributed actor. They are useful investigative context, but the campaign source does not necessarily link every item directly to this campaign.

Investigation context

What the attributed actors are known to use

Use this material to guide hunting and prioritization, then confirm each relationship against its cited source.

Malware and tools 49

  • BoomBoxMalware | APT29
  • CloudDukeMalware | APT29
  • Cobalt StrikeMalware | APT29
  • CosmicDukeMalware | APT29
  • CozyCarMalware | APT29
  • EnvyScoutMalware | APT29
  • FatDukeMalware | APT29
  • FoggyWebMalware | APT29
  • GeminiDukeMalware | APT29
  • GoldFinderMalware | APT29
  • GoldMaxMalware | APT29
  • HAMMERTOSSMalware | APT29

Indicators 0

No source-linked indicators are available.

Sources

Evidence behind this page

Open the original material before making an attribution or response decision.

Continue investigating

Campaigns with shared actors