ATT&CKCampaignsSolarWinds Compromise

SolarWinds Compromise

C0024

Campaign, Aug 2019 to Jan 2021.View on attack.mitre.org

About this campaign

The SolarWinds Compromise was a sophisticated supply chain cyber operation conducted by APT29 that was discovered in mid-December 2020. APT29 used customized malware to inject malicious code into the SolarWinds Orion software build process that was later distributed through a normal software update; they also used password spraying, token theft, API abuse, spear phishing, and other supply chain attacks to compromise user accounts and leverage their associated access. Victims of this campaign included government, consulting, technology, telecom, and other organizations in North America, Europe, Asia, and the Middle East. This activity has been labled the StellarParticle campaign in industry reporting. Industry reporting also initially referred to the actors involved in this campaign as UNC2452, NOBELIUM, Dark Halo, and SolarStorm.

In April 2021, the US and UK governments attributed the SolarWinds Compromise to Russia's Foreign Intelligence Service (SVR); public statements included citations to APT29, Cozy Bear, and The Dukes. The US government assessed that of the approximately 18,000 affected public and private sector customers of Solar Winds’ Orion product, a much smaller number were compromised by follow-on APT29 activity on their systems.

Techniques used71

Procedure examples71

TechniqueProcedure example
T1003.006
DCSync

During the SolarWinds Compromise, APT29 used privileged accounts to replicate directory service data with domain controllers.

T1005
Data from Local System

During the SolarWinds Compromise, APT29 extracted files from compromised networks.

T1016.001
Internet Connection Discovery

During the SolarWinds Compromise, APT29 used GoldFinder to perform HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request travels through.

T1018
Remote System Discovery

During the SolarWinds Compromise, APT29 used AdFind to enumerate remote systems.

T1021.001
Remote Desktop Protocol

During the SolarWinds Compromise, APT29 used RDP sessions from public-facing systems to internal servers.

T1021.002
SMB/Windows Admin Shares

During the SolarWinds Compromise, APT29 used administrative accounts to connect over SMB to targeted users.

T1021.006
Windows Remote Management

During the SolarWinds Compromise, APT29 used WinRM via PowerShell to execute commands and payloads on remote hosts.

T1036.004
Masquerade Task or Service

During the SolarWinds Compromise, APT29 named tasks `\Microsoft\Windows\SoftwareProtectionPlatform\EventCacheManager` in order to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location

During the SolarWinds Compromise, APT29 renamed software and DLLs with legitimate names to appear benign.

T1047
Windows Management Instrumentation

During the SolarWinds Compromise, APT29 used WMI for the remote execution of files for lateral movement.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol

During the SolarWinds Compromise, APT29 exfiltrated collected data over a simple HTTPS request to a password-protected archive staged on a victim's OWA servers.

T1053.005
Scheduled Task

During the SolarWinds Compromise, APT29 used `scheduler` and `schtasks` to create new tasks on remote host as part of their lateral movement. They manipulated scheduled tasks by updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration. APT29 also created a scheduled task to maintain SUNSPOT persistence when the host booted.

T1057
Process Discovery

During the SolarWinds Compromise, APT29 used multiple command-line utilities to enumerate running processes.

T1059.001
PowerShell

During the SolarWinds Compromise, APT29 used PowerShell to create new tasks on remote machines, identify configuration settings, exfiltrate data, and execute other commands.

T1059.003
Windows Command Shell

During the SolarWinds Compromise, APT29 used `cmd.exe` to execute commands on remote machines.

View all 71 procedure examples

Attributed groups1

Software11

References12

  1. CrowdStrike StellarParticle January 2022 Open source
    CrowdStrike. (2022, January 27). Early Bird Catches the Wormhole: Observations from the StellarParticle Campaign. Retrieved February 7, 2022.
  2. FireEye SUNBURST Backdoor December 2020 Open source
    FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.
  3. Mandiant UNC2452 APT29 April 2022 Open source
    Mandiant. (2022, April 27). Assembling the Russian Nesting Doll: UNC2452 Merged into APT29. Retrieved March 26, 2023.
  4. Microsoft Analyzing Solorigate Dec 2020 Open source
    MSTIC. (2020, December 18). Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers . Retrieved January 5, 2021.
  5. Microsoft Internal Solorigate Investigation Blog Open source
    MSRC Team. (2021, February 18). Microsoft Internal Solorigate Investigation – Final Update. Retrieved May 14, 2021.
  6. NSA Joint Advisory SVR SolarWinds April 2021 Open source
    NSA, FBI, DHS. (2021, April 15). Russian SVR Targets U.S. and Allied Networks. Retrieved April 16, 2021.
  7. SolarWinds Advisory Dec 2020 Open source
    SolarWinds. (2020, December 24). SolarWinds Security Advisory. Retrieved February 22, 2021.
  8. SolarWinds Sunburst Sunspot Update January 2021 Open source
    Sudhakar Ramakrishna . (2021, January 11). New Findings From Our Investigation of SUNBURST. Retrieved January 13, 2021.
  9. UK NSCS Russia SolarWinds April 2021 Open source
    UK NCSC. (2021, April 15). UK and US call out Russia for SolarWinds compromise. Retrieved April 16, 2021.
  10. USG Joint Statement SolarWinds January 2021 Open source
    FBI, CISA, ODNI, NSA. (2022, January 5). Joint Statement by the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Office of the Director of National Intelligence (ODNI), and the National Security Agency (NSA). Retrieved March 26, 2023.
  11. Unit 42 SolarStorm December 2020 Open source
    Unit 42. (2020, December 23). SolarStorm Supply Chain Attack Timeline. Retrieved March 24, 2023.
  12. Volexity SolarWinds Open source
    Cash, D. et al. (2020, December 14). Dark Halo Leverages SolarWinds Compromise to Breach Organizations. Retrieved December 29, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.