Cybersecurity

Inside SolarWinds: How Hackers Turned a Trusted Software Update Into a Nation-State Backdoor

In December 2020, cybersecurity company FireEye discovered that its own red-team tools had been stolen. As investigators dug deeper, they…

September 8, 2026·5 min read
Inside SolarWinds: How Hackers Turned a Trusted Software Update Into a Nation-State Backdoor

In December 2020, cybersecurity company FireEye discovered that its own red-team tools had been stolen. As investigators dug deeper, they realized FireEye wasn’t the real target. They had uncovered one of the most sophisticated supply-chain attacks ever seen — an operation that had quietly infiltrated U.S. government agencies, Fortune 500 companies, and thousands of other organizations for months.

The entry point wasn’t a phishing email or a leaked password. It was a routine software update from SolarWinds.

The Real Target Was the Vendor

SolarWinds develops IT management software, and its flagship product, Orion, is widely used to monitor networks and infrastructure. More than 30,000 public and private organizations relied on Orion, including federal agencies and major corporations.

That trust made SolarWinds the perfect target. Rather than compromise thousands of organizations individually, attackers — widely attributed to the Russian state-linked group APT29 (Cozy Bear) — focused on a single company whose software was already trusted everywhere.

•••

Stage 1: Compromising the Build Pipeline

Instead of attacking Orion itself, the attackers gained access to SolarWinds’ software build environment — the system responsible for compiling source code into customer-ready releases.

They inserted malicious code into the build process so that infected Orion versions were generated automatically during compilation. The malware was embedded inside SolarWinds.Orion.Core.BusinessLayer.dll and shipped as part of legitimate software releases.

Most importantly, the modified files were signed using SolarWinds’ legitimate digital certificate. To customers and security products, the malware appeared to be trusted vendor software because, technically, it was.

This backdoor became known as Sunburst.

Stage 2: Distribution Through Trusted Updates

Once embedded in Orion, Sunburst spread through SolarWinds’ normal update mechanism.

More than 18,000 customers installed versions containing the malicious code. No antivirus alerts were triggered, and nothing appeared suspicious because the update came directly from a trusted vendor.

This is the essence of a supply-chain attack: compromise the source everyone trusts instead of attacking each target individually.

Stage 3: Staying Dormant

After installation, Sunburst remained inactive for roughly two weeks.

This delay was intentional. Many automated malware-analysis systems observe new software only briefly before concluding it is safe. By waiting days before activating, the malware avoided triggering those defenses.

Before taking further action, Sunburst also performed environmental checks to ensure it was operating in a suitable target environment and to reduce the risk of detection.

Stage 4: Blending Into Normal Traffic

When Sunburst began communicating with its operators, it used DNS traffic designed to resemble normal Orion activity.

Because Orion already generated network-monitoring traffic, the malware’s communications blended naturally into existing network behavior. To defenders, the traffic looked like legitimate software functioning as expected.

This made detection extremely difficult, even for mature security teams.

Stage 5: Human-Led Exploitation

Not every infected organization became a full victim.

Of the roughly 18,000 compromised installations, only a small number were selected for deeper exploitation. For those targets, Sunburst served as an entry point rather than the final objective.

Human operators deployed additional malware, including Teardrop, which delivered tools such as Cobalt Strike for command-and-control, persistence, and lateral movement.

At this stage, the campaign shifted from automated malware deployment to hands-on intrusion conducted by skilled operators.

Stage 6: Targeting Identity Systems

One of the most damaging aspects of the campaign involved identity infrastructure.

In several cases, attackers compromised Active Directory Federation Services (ADFS), which organizations use to provide single sign-on access to services such as Microsoft 365.

By obtaining ADFS token-signing keys, attackers could forge valid SAML authentication tokens. This allowed them to impersonate users — including administrators — without knowing their passwords.

With trusted authentication tokens, they could access email, cloud services, and sensitive data while appearing to be legitimate users.

•••

Why the Attack Was So Effective

Three factors made Sunburst exceptionally difficult to detect:

It Abused Trust

There was no traditional software vulnerability to patch. The attackers compromised the software supply chain itself, turning a trusted update mechanism into a delivery system for malware.

It Was Patient

The two-week dormancy period allowed the malware to evade many automated security systems designed to identify suspicious behavior shortly after installation.

It Hid Within Expected Behavior

From legitimate code signing to carefully disguised DNS traffic, nearly every indicator appeared normal because the attackers intentionally designed it that way.

It’s also worth noting that a separate group, believed to be China-linked, later exploited a different Orion vulnerability using malware known as Supernova. Although it involved the same product, it was unrelated to the Sunburst campaign.

Lessons for Defenders

The SolarWinds incident demonstrates that some of the most dangerous attacks don’t target production systems directly — they target the processes used to build and distribute trusted software.

A few key lessons stand out:

  • Treat build and deployment pipelines as critical security boundaries.

  • Remember that code signing proves authenticity, not integrity of the development process.

  • Focus on behavioral monitoring rather than relying solely on signatures.

  • Protect identity systems aggressively, because forged authentication tokens can bypass many traditional security controls.

  • Apply least-privilege principles throughout both infrastructure and identity environments.

SolarWinds wasn’t successful because defenders ignored obvious warnings. It succeeded because the attackers compromised a trust relationship that nearly everyone assumed was secure.

That remains one of the most important lessons in modern cybersecurity.

Comments

No comments yet.