SUNBURST

MITRE ATT&CK: S0559 View on attack.mitre.org

Aliases: Solorigate, SUNBURST

Malware type
trojan, backdoor
Family
Malware family
Operating systems
windows
Related IoCs
17 (13 malicious)
Last IoC activity
2026-09-02 01:23:13
Profile updated
2026-07-07 12:37:37

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services energy-and-utilities healthcare-and-pharmaceutical

Targeted regions: country_code:us country_code:gb country_code:de

Context

SUNBURST is a trojanized DLL designed to fit within the SolarWinds Orion software update framework. It was used by APT29 since at least February 2020.

Recent IoC activity

13 malicious indicators in Maltiverse are attributed to SUNBURST (S0559). The 13 most recently updated:

TypeIndicatorUpdatedSources
hostname digitalcollege.org 2026-09-03 4
hostname highdatabase.com 2026-09-02 3
hostname zupertech.com 2026-09-02 4
hostname websitetheme.com 2026-09-02 3
hostname databasegalore.com 2026-09-02 4
hostname deftsecurity.com 2026-09-02 4
hostname freescanonline.com 2026-09-02 4
hostname thedoccloud.com 2026-09-02 4
hostname virtualdataserver.com 2026-09-02 4
file sample file 2026-08-15 2
file sample 2ade1ac8911ad6a23498230a5e119516db47f6e76687f804e2512cc9bcfda2b0.dll 2026-07-10 2
file sample task5.zip 2026-07-09 1
file sample 42e73c85b07d89956e94db832d6501c823ae00684c50d9c9163194357c3dd3ed 2026-05-01 2

Detection coverage

  • 3 YARA rules
  • 728 Sigma rules

Malware & tools used

  • Time Based Checks (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Modify Registry (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Clear Persistence (attack-pattern)
  • Data from Local System (attack-pattern)
  • System Time Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Image File Execution Options Injection (attack-pattern)
  • Rundll32 (attack-pattern)
  • Compression (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Code Signing (attack-pattern)
  • Process Discovery (attack-pattern)
  • Protocol or Service Impersonation (attack-pattern)
  • Junk Data (attack-pattern)
  • Visual Basic (attack-pattern)
  • DNS (attack-pattern)
  • File Deletion (attack-pattern)

Used by threat actors

  • APT29 (threat-actor)
  • SolarWinds Compromise (campaign)

Detection rules

  • SBOUSSEADEN_APT_Solarwind_Backdoor_Encoded_Strings (yara-rule)
  • SIGNATURE_BASE_APT_Backdoor_SUNBURST_1 (yara-rule)
  • SIGNATURE_BASE_APT_Backdoor_SUNBURST_2 (yara-rule)

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • CrowdStrike — Report2021Gtr (report)
  • medium.com — Identifying Unc2452 Related Techniques 9F7B6C7F3714 (report)
  • Mandiant — Evasive Attacker Leverages Solarwinds Supply Chain Compromises With Sunburst Backdoor (report)
  • news.sophos.com — How Sunburst Malware Does Defense Evasion (report)
  • Microsoft — Analyzing Solorigate The Compromised Dll File That Started A Sophisticated Cyberattack And How Microsoft Defender Helps Protect (report)
  • pastebin.com — 6Edgckxd (report)
  • github.com — Sunburst Countermeasures (report)
  • Microsoft — Goldmax Goldfinder Sibot Analyzing Nobelium Malware (report)
  • Palo Alto Unit 42 — Solarphoenix (report)
  • Palo Alto Unit 42 — Solarstorm Supply Chain Attack Timeline (report)
  • CrowdStrike — Sunspot Malware Technical Analysis (report)
  • volexity.com — Dark Halo Leverages Solarwinds Compromise To Breach Organizations (report)
  • Palo Alto Unit 42 — Strategically Aged Domain Detection (report)
  • 0xc0decafe.com — Malware Analyst Guide To Pe Timestamps (report)
  • cert.pl — Kampania Szpiegowska Apt29 (report)
  • domaintools.com — Conceptualizing A Continuum Of Cyber Threat Attribution (report)
  • brighttalk.com — 462719 (report)
  • Mandiant — Unc2452 Merged Into Apt29 (report)
  • youtube.com — Watch (report)
  • Mandiant — Download (report)
  • Microsoft — Deep Dive Into The Solorigate Second Stage Activation From Sunburst To Teardrop And Raindrop (report)
  • orangematter.solarwinds.com — New Findings From Our Investigation Of Sunburst (report)
  • youtube.com — Watch (report)
  • github.com — Solarwinds Threathunt (report)

External references