What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Attackers used persistent access to SolarWinds’ development and build environment to insert the SUNBURST backdoor into a limited set of legitimate Orion software updates. That turned SolarWinds’ trusted update channel into an initial foothold for espionage—but downloading an affected update did not, by itself, mean an organization was confirmed hacked.

How did hackers get into SolarWinds Orion?

SolarWinds said the attackers did not change the Orion source-code repository. Instead, they compromised the automated build environment—the systems and processes that turn software source code into releases—and used a tool called SUNSPOT to inject SUNBURST into the resulting Orion builds.

In its investigation update, SolarWinds said: “The threat actor did not modify our source code repository.” The company also described the malicious activity as occurring “within the automated build environment for our Orion Platform software.” These are the company’s findings, not an independent forensic conclusion.

In practical terms, the attackers interfered with the production process rather than making an obvious change in the source files developers worked on. The resulting binaries were legitimate Orion releases distributed through the normal update channel. Customers who installed an affected release could therefore receive the backdoor through a trusted software update.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

What SUNSPOT and SUNBURST did

  • SUNSPOT was the injector SolarWinds identified in the compromised build environment. It was used to insert malicious code into Orion builds.
  • SUNBURST was the backdoor placed in the affected Orion software. Microsoft’s analysis also refers to the incident as Solorigate and notes that FireEye called the backdoor SUNBURST.

When did the SolarWinds attack happen?

SolarWinds’ account describes activity extending from 2019 into December 2020. The dates below come from the company’s investigation updates; they mark reported milestones, not necessarily every attacker action.

Date What SolarWinds reported
September 2019 The earliest suspicious activity on SolarWinds’ internal systems identified in the company’s investigation.
October 2019 A test run assessed the attackers’ ability to inject code into Orion builds.
February 20, 2020 SolarWinds said an updated version of the malicious code-injection source began inserting SUNBURST into Orion releases.
March–June 2020 The period in which SolarWinds said the affected Orion versions were released.
June 2020 SolarWinds said the attackers removed SUNBURST code from the environment. Microsoft later described selected-target follow-on activity and a shift to second-stage operations.
December 12, 2020 SolarWinds said it was informed of the attack and began notifying customers and investigating.

Which Orion versions were affected?

SolarWinds identified three affected Orion releases: 2019.4 HF 5, 2020.2 unpatched, and 2020.2 HF 1. The company placed their relevant release period between March and June 2020. This is a specific set of versions, not a claim that every Orion release or every SolarWinds product was compromised.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

How many organizations were actually hacked through SUNBURST?

SolarWinds initially said that up to 18,000 downloads of affected Orion versions could have been vulnerable. That figure referred to potentially vulnerable downloads, not 18,000 confirmed victims. In a later estimate, SolarWinds said fewer than 100 customers had been hacked through SUNBURST. Both figures are company estimates from 2020, and they describe different stages of impact: possible exposure through downloads versus customers the company estimated were actually compromised.

The distinction matters because a backdoor reaching an organization’s systems was not the same as attackers successfully using it to compromise that organization. Microsoft described follow-on activity in selected targets rather than treating every potentially vulnerable installation as an actual intrusion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

What happened after SUNBURST reached a network?

SUNBURST was an initial foothold, not the entirety of the operation. Microsoft’s analysis describes cases in which attackers moved from the backdoor to hands-on-keyboard activity and second-stage tooling, including Cobalt Strike loaders named TEARDROP and Raindrop. Those details concern observed follow-on activity; Microsoft noted that its handover analysis drew on a limited number of cases, so they should not be read as a universal sequence for every affected organization.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Who was behind the SolarWinds cyberattack?

Microsoft’s February 2021 update said its Microsoft Threat Intelligence Center named the actor behind the SolarWinds attack and related components NOBELIUM. SolarWinds, in its investigation update, said it had not independently verified the perpetrators’ identity. The attribution should therefore be stated as Microsoft’s naming, alongside SolarWinds’ caveat, rather than as a conclusion independently confirmed by SolarWinds.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

How was SUNBURST different from SUPERNOVA?

Malware How it was introduced What distinguishes it
SUNBURST Inserted into Orion software builds in the compromised automated build environment. A supply-chain backdoor delivered through affected Orion updates.
SUPERNOVA SolarWinds said it was placed separately on a customer server after unauthorized access to that customer’s network. It was not malicious code embedded in Orion builds as a supply-chain attack.

SolarWinds’ distinction is about how the malware got onto systems: SUNBURST was embedded in software builds, while SUPERNOVA required separate unauthorized access to a customer network.

Sources

  • SolarWinds, Security Advisory FAQ, for affected versions and the SUNBURST/SUPERNOVA distinction.
  • SolarWinds, An Investigative Update of the Cyberattack, for the build compromise, SUNSPOT, and impact estimates.
  • SolarWinds, New Findings From Our Investigation of SUNBURST, for the timeline and attribution caveat.
  • Microsoft Security Team, Microsoft open sources CodeQL queries used to hunt for Solorigate activity (February 25, 2021), for the NOBELIUM designation and post-compromise capabilities.
  • Microsoft Security Team, Deep dive into the Solorigate second-stage activation (January 20, 2021), for second-stage loaders and the observed handover.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.