SUPERNOVA

MITRE ATT&CK: S0578 View on attack.mitre.org

Aliases: SUPERNOVA

Malware type
webshell
Family
Malware family
Operating systems
windows
Related IoCs
2 (2 malicious)
Last IoC activity
2026-07-02 06:29:25
Profile updated
2026-07-07 12:38:15

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

SUPERNOVA is an in-memory web shell written in .NET C#. It was discovered in November 2020 during the investigation of APT29's SolarWinds cyber operation but determined to be unrelated. Subsequent analysis suggests SUPERNOVA may have been used by the China-based threat group SPIRAL.

Recent IoC activity

2 malicious indicators in Maltiverse are attributed to SUPERNOVA (S0578). The 2 most recently updated:

Detection coverage

  • 3 YARA rules
  • 87 Sigma rules

Malware & tools used

  • Web Protocols (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Web Shell (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)

Detection rules

  • SIGNATURE_BASE_APT_Webshell_SUPERNOVA_1 (yara-rule)
  • SIGNATURE_BASE_APT_Webshell_SUPERNOVA_2 (yara-rule)
  • MALPEDIA_Win_Supernova_Auto (yara-rule)

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • Mandiant — Evasive Attacker Leverages Solarwinds Supply Chain Compromises With Sunburst Backdoor (report)
  • Microsoft — Analyzing Solorigate The Compromised Dll File That Started A Sophisticated Cyberattack And How Microsoft Defender Helps Protect (report)
  • github.com — Sunburst Countermeasures (report)
  • Palo Alto Unit 42 — Solarstorm Supernova (report)
  • guidepointsecurity.com — Supernova Solarwinds Net Webshell Analysis (report)
  • secureworks.com — Supernova Web Shell Deployment Linked To Spiral Threat Group (report)
  • sentinelone.com — Solarwinds Understanding Detecting The Supernova Webshell Trojan (report)
  • CISA — Ar21 027A (report)
  • CISA — Ar21 112A (report)
  • solarwinds.com — Faq (report)
  • CISA — Aa21 008A (report)
  • solarwinds.com — Securityadvisory (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Supernova (report)
  • splunk.com — Supernova Redux With A Generous Portion Of Masquerading (report)
  • youtube.com — Watch (report)
  • guidepointsecurity.com — Supernova Solarwinds Net Webshell Analysis (report)
  • Trend Micro — Overview Of Recent Sunburst Targeted Attacks (report)
  • labs.sentinelone.com — Solarwinds Understanding Detecting The Supernova Webshell Trojan (report)
  • anquanke.com — 226029 (report)
  • CISA — Ar21 112A (report)
  • twitter.com — 1342888881373503488 (report)
  • splunk.com — Detecting Supernova Malware Solarwinds Continued (report)
  • github.com — 5 (report)
  • MITRE ATT&CK — S0578 (report)

External references