Campaign, Aug 2019 to Jan 2021.View on attack.mitre.org
The SolarWinds Compromise was a sophisticated supply chain cyber operation conducted by APT29 that was discovered in mid-December 2020. APT29 used customized malware to inject malicious code into the SolarWinds Orion software build process that was later distributed through a normal software update; they also used password spraying, token theft, API abuse, spear phishing, and other supply chain attacks to compromise user accounts and leverage their associated access. Victims of this campaign included government, consulting, technology, telecom, and other organizations in North America, Europe, Asia, and the Middle East. This activity has been labled the StellarParticle campaign in industry reporting. Industry reporting also initially referred to the actors involved in this campaign as UNC2452, NOBELIUM, Dark Halo, and SolarStorm.
In April 2021, the US and UK governments attributed the SolarWinds Compromise to Russia's Foreign Intelligence Service (SVR); public statements included citations to APT29, Cozy Bear, and The Dukes. The US government assessed that of the approximately 18,000 affected public and private sector customers of Solar Winds’ Orion product, a much smaller number were compromised by follow-on APT29 activity on their systems.
| Technique | Procedure example |
|---|---|
| T1003.006 DCSync |
During the SolarWinds Compromise, APT29 used privileged accounts to replicate directory service data with domain controllers. |
| T1005 Data from Local System |
During the SolarWinds Compromise, APT29 extracted files from compromised networks. |
| T1016.001 Internet Connection Discovery |
During the SolarWinds Compromise, APT29 used GoldFinder to perform HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request travels through. |
| T1018 Remote System Discovery |
During the SolarWinds Compromise, APT29 used AdFind to enumerate remote systems. |
| T1021.001 Remote Desktop Protocol |
During the SolarWinds Compromise, APT29 used RDP sessions from public-facing systems to internal servers. |
| T1021.002 SMB/Windows Admin Shares |
During the SolarWinds Compromise, APT29 used administrative accounts to connect over SMB to targeted users. |
| T1021.006 Windows Remote Management |
During the SolarWinds Compromise, APT29 used WinRM via PowerShell to execute commands and payloads on remote hosts. |
| T1036.004 Masquerade Task or Service |
During the SolarWinds Compromise, APT29 named tasks `\Microsoft\Windows\SoftwareProtectionPlatform\EventCacheManager` in order to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
During the SolarWinds Compromise, APT29 renamed software and DLLs with legitimate names to appear benign. |
| T1047 Windows Management Instrumentation |
During the SolarWinds Compromise, APT29 used WMI for the remote execution of files for lateral movement. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
During the SolarWinds Compromise, APT29 exfiltrated collected data over a simple HTTPS request to a password-protected archive staged on a victim's OWA servers. |
| T1053.005 Scheduled Task |
During the SolarWinds Compromise, APT29 used `scheduler` and `schtasks` to create new tasks on remote host as part of their lateral movement. They manipulated scheduled tasks by updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration. APT29 also created a scheduled task to maintain SUNSPOT persistence when the host booted. |
| T1057 Process Discovery |
During the SolarWinds Compromise, APT29 used multiple command-line utilities to enumerate running processes. |
| T1059.001 PowerShell |
During the SolarWinds Compromise, APT29 used PowerShell to create new tasks on remote machines, identify configuration settings, exfiltrate data, and execute other commands. |
| T1059.003 Windows Command Shell |
During the SolarWinds Compromise, APT29 used `cmd.exe` to execute commands on remote machines. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.