SUNBURST
MITRE ATT&CK: S0559 View on attack.mitre.org
Aliases: Solorigate, SUNBURST
- Malware type
- trojan, backdoor
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 17 (13 malicious)
- Last IoC activity
- 2026-09-02 01:23:13
- Profile updated
- 2026-07-07 12:37:37
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services energy-and-utilities healthcare-and-pharmaceutical
Targeted regions: country_code:us country_code:gb country_code:de
Context
SUNBURST is a trojanized DLL designed to fit within the SolarWinds Orion software update framework. It was used by APT29 since at least February 2020.
Recent IoC activity
13 malicious indicators in Maltiverse are attributed to SUNBURST (S0559). The 13 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | digitalcollege.org | 2026-09-03 | 4 |
| hostname | highdatabase.com | 2026-09-02 | 3 |
| hostname | zupertech.com | 2026-09-02 | 4 |
| hostname | websitetheme.com | 2026-09-02 | 3 |
| hostname | databasegalore.com | 2026-09-02 | 4 |
| hostname | deftsecurity.com | 2026-09-02 | 4 |
| hostname | freescanonline.com | 2026-09-02 | 4 |
| hostname | thedoccloud.com | 2026-09-02 | 4 |
| hostname | virtualdataserver.com | 2026-09-02 | 4 |
| file sample | file | 2026-08-15 | 2 |
| file sample | 2ade1ac8911ad6a23498230a5e119516db47f6e76687f804e2512cc9bcfda2b0.dll | 2026-07-10 | 2 |
| file sample | task5.zip | 2026-07-09 | 1 |
| file sample | 42e73c85b07d89956e94db832d6501c823ae00684c50d9c9163194357c3dd3ed | 2026-05-01 | 2 |
Detection coverage
- 3 YARA rules
- 728 Sigma rules
Malware & tools used
- Time Based Checks (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- System Information Discovery (attack-pattern)
- Modify Registry (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Standard Encoding (attack-pattern)
- Clear Persistence (attack-pattern)
- Data from Local System (attack-pattern)
- System Time Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Image File Execution Options Injection (attack-pattern)
- Rundll32 (attack-pattern)
- Compression (attack-pattern)
- System Service Discovery (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Code Signing (attack-pattern)
- Process Discovery (attack-pattern)
- Protocol or Service Impersonation (attack-pattern)
- Junk Data (attack-pattern)
- Visual Basic (attack-pattern)
- DNS (attack-pattern)
- File Deletion (attack-pattern)
Used by threat actors
- APT29 (threat-actor)
- SolarWinds Compromise (campaign)
Detection rules
- SBOUSSEADEN_APT_Solarwind_Backdoor_Encoded_Strings (yara-rule)
- SIGNATURE_BASE_APT_Backdoor_SUNBURST_1 (yara-rule)
- SIGNATURE_BASE_APT_Backdoor_SUNBURST_2 (yara-rule)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- CrowdStrike — Report2021Gtr (report)
- medium.com — Identifying Unc2452 Related Techniques 9F7B6C7F3714 (report)
- Mandiant — Evasive Attacker Leverages Solarwinds Supply Chain Compromises With Sunburst Backdoor (report)
- news.sophos.com — How Sunburst Malware Does Defense Evasion (report)
- Microsoft — Analyzing Solorigate The Compromised Dll File That Started A Sophisticated Cyberattack And How Microsoft Defender Helps Protect (report)
- pastebin.com — 6Edgckxd (report)
- github.com — Sunburst Countermeasures (report)
- Microsoft — Goldmax Goldfinder Sibot Analyzing Nobelium Malware (report)
- Palo Alto Unit 42 — Solarphoenix (report)
- Palo Alto Unit 42 — Solarstorm Supply Chain Attack Timeline (report)
- CrowdStrike — Sunspot Malware Technical Analysis (report)
- volexity.com — Dark Halo Leverages Solarwinds Compromise To Breach Organizations (report)
- Palo Alto Unit 42 — Strategically Aged Domain Detection (report)
- 0xc0decafe.com — Malware Analyst Guide To Pe Timestamps (report)
- cert.pl — Kampania Szpiegowska Apt29 (report)
- domaintools.com — Conceptualizing A Continuum Of Cyber Threat Attribution (report)
- brighttalk.com — 462719 (report)
- Mandiant — Unc2452 Merged Into Apt29 (report)
- youtube.com — Watch (report)
- Mandiant — Download (report)
- Microsoft — Deep Dive Into The Solorigate Second Stage Activation From Sunburst To Teardrop And Raindrop (report)
- orangematter.solarwinds.com — New Findings From Our Investigation Of Sunburst (report)
- youtube.com — Watch (report)
- github.com — Solarwinds Threathunt (report)
External references
- mitre-attack — S0559
- SUNBURST
- Solorigate
- FireEye SUNBURST Backdoor December 2020
- Microsoft Deep Dive Solorigate January 2021
- SolarWinds Sunburst Sunspot Update January 2021
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy