Overview
Attackers modified the SolarWinds Orion build process so signed updates carried a dormant backdoor called SUNBURST.\nRoughly 18,000 organisations installed it; the operators then selected a few hundred for hands-on access to email and source code.\nDetection was hard because the malware mimicked normal Orion traffic and waited weeks before activating.\nIt reset how the industry thinks about build pipelines and software provenance.
Indicators of Compromise
Signals that suggest this is present on a system.
- Orion binaries with unexpected SHA hashes
- Delayed DNS lookups mimicking legitimate subdomains
- New service accounts created in cloud tenants