SUPERNOVA
MITRE ATT&CK: S0578 View on attack.mitre.org
Aliases: SUPERNOVA
- Malware type
- webshell
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 2 (2 malicious)
- Last IoC activity
- 2026-07-02 06:29:25
- Profile updated
- 2026-07-07 12:38:15
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
SUPERNOVA is an in-memory web shell written in .NET C#. It was discovered in November 2020 during the investigation of APT29's SolarWinds cyber operation but determined to be unrelated. Subsequent analysis suggests SUPERNOVA may have been used by the China-based threat group SPIRAL.
Recent IoC activity
2 malicious indicators in Maltiverse are attributed to SUPERNOVA (S0578). The 2 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | e9593a8ae506ffce10c15b37a57e2e1f09458a37439b53365991a6f8df646837.bin | 2026-07-02 | 3 |
| file sample | 1c96021ac8cb52173e762f6b008fb4c6e5ef113e6baa4e2cf4848e88c61d9700 | 2026-04-29 | 2 |
Detection coverage
- 3 YARA rules
- 87 Sigma rules
Malware & tools used
- Web Protocols (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Web Shell (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
Detection rules
- SIGNATURE_BASE_APT_Webshell_SUPERNOVA_1 (yara-rule)
- SIGNATURE_BASE_APT_Webshell_SUPERNOVA_2 (yara-rule)
- MALPEDIA_Win_Supernova_Auto (yara-rule)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- Mandiant — Evasive Attacker Leverages Solarwinds Supply Chain Compromises With Sunburst Backdoor (report)
- Microsoft — Analyzing Solorigate The Compromised Dll File That Started A Sophisticated Cyberattack And How Microsoft Defender Helps Protect (report)
- github.com — Sunburst Countermeasures (report)
- Palo Alto Unit 42 — Solarstorm Supernova (report)
- guidepointsecurity.com — Supernova Solarwinds Net Webshell Analysis (report)
- secureworks.com — Supernova Web Shell Deployment Linked To Spiral Threat Group (report)
- sentinelone.com — Solarwinds Understanding Detecting The Supernova Webshell Trojan (report)
- CISA — Ar21 027A (report)
- CISA — Ar21 112A (report)
- solarwinds.com — Faq (report)
- CISA — Aa21 008A (report)
- solarwinds.com — Securityadvisory (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Supernova (report)
- splunk.com — Supernova Redux With A Generous Portion Of Masquerading (report)
- youtube.com — Watch (report)
- guidepointsecurity.com — Supernova Solarwinds Net Webshell Analysis (report)
- Trend Micro — Overview Of Recent Sunburst Targeted Attacks (report)
- labs.sentinelone.com — Solarwinds Understanding Detecting The Supernova Webshell Trojan (report)
- anquanke.com — 226029 (report)
- CISA — Ar21 112A (report)
- twitter.com — 1342888881373503488 (report)
- splunk.com — Detecting Supernova Malware Solarwinds Continued (report)
- github.com — 5 (report)
- MITRE ATT&CK — S0578 (report)
External references
- mitre-attack — S0578
- CISA Supernova Jan 2021
- Microsoft Analyzing Solorigate Dec 2020
- Guidepoint SUPERNOVA Dec 2020
- SolarWinds Advisory Dec 2020
- Unit42 SUPERNOVA Dec 2020
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy