Breaches and Incidents

Highly Elusive Attackers Leverage SolarWinds Supply Chain to Compromise Victims With SUNBURST Backdoor

Verified Officially confirmed

A recent breach involving a cybersecurity firm FireEye has uncovered a widespread campaign by an uncategorised advanced persistent threat actor tracked as UNC2452 by FireEye. The actors behind this campaign have gained access to numerous public and private organisations around the world via trojanised updates to SolarWinds’ Orion IT monitoring and management software.

First observed
15 Dec 2020
Last checked
01 Aug 2026
Evidence records
1
Publication state
Published

What happened?

Current assessment

A recent breach involving a cybersecurity firm FireEye has uncovered a widespread campaign by an uncategorised advanced persistent threat actor tracked as UNC2452 by FireEye. The actors behind this campaign have gained access to numerous public and private organisations around the world via trojanised updates to SolarWinds’ Orion IT monitoring and management software.

Why it matters

Information leakage, information exposure.

Who is affected?

Affected products and groups

  • Software: SolarWinds' Orion Platform versions 2019.4 through 2020.2.1 HF1.

What should you do now?

Actions from official guidance

For technical teams

  1. Agencies that have the capabilities to handle the situation to take the following actions immediately: Official source
  2. To create copies of system memory and/or host operating systems hosting all instances of SolarWinds Orion versions 2019.4 through 2020.2.1 HF1; Analyse for new user or service accounts, privileged or otherwise; Analyse stored network traffic for indicators of compromise (IoC), including new external DNS domains that have had connections to IoC. Indicators of compromise are listed above; Restrict the scope of connectivity to critical endpoints from SolarWind servers; Restrict the scope of accounts that have local administrator privileged on SolarWind servers; and Apply the new hotfix issued by SolarWinds version 2020.2.1 HF2. Official source
  3. Affected agencies that have limited capabilities to handle the situation shall immediately disconnect or power down SolarWinds Orion products, versions 2019.4 through 2020.2.1 HF1, from their network. Official source
  4. NC4 recommends that affected agencies rebuild the Windows operating system and reinstall the SolarWinds software package from trusted sources; and Agencies are prohibited from re-joining the Windows host OS to the enterprise domain until proper clean-up has been done and the new hotfix issued out by SolarWinds is applied – version 2020.2.1 HF2. Official source
  5. Block all traffic to and from hosts, external to the enterprise, where any version of SolarWinds Orion software has been installed; Official source
  6. Identify and remove all threat actor-controlled accounts and identified persistence mechanisms; and Official source
  7. After all threat actor-controlled accounts have been deleted, reset all credentials used by or stored in SolarWinds software. Official source

Which sources support it?

Evidence and official sources

  1. NACSA / NC4 Alerts and AdvisoriesOfficial source
    Highly Elusive Attackers Leverage SolarWinds Supply Chain to Compromise Victims With SUNBURST Backdoor

    A recent breach involving a cybersecurity firm FireEye has uncovered a widespread campaign by an uncategorised advanced persistent threat actor tracked as UNC2452 by FireEye. The actors behind this campaign have gained access to numerous public and private organisations around the world via trojanised updates to SolarWinds’ Orion IT monitoring and management software.

    Published 15 Dec 2020 · Retrieved 01 Aug 2026