Overview
The SolarWinds Compromise (MITRE ATT&CK ID C0024) was a sophisticated supply-chain cyber operation conducted by APT29, discovered in mid-December 2020, per MITRE’s campaign profile. MITRE documents APT29 as using customized malware to inject malicious code into the SolarWinds Orion software build process, later distributed through a normal software update — alongside password spraying, token theft, API abuse, spear phishing, and other supply-chain attacks to compromise user accounts and leverage their associated access. Victims spanned government, consulting, technology, telecom, and other organizations across North America, Europe, Asia, and the Middle East. MITRE notes this activity has been labeled the “StellarParticle” campaign in industry reporting, and was also initially referred to as UNC2452, NOBELIUM, Dark Halo, and SolarStorm.
In April 2021, per MITRE’s citations, the US and UK governments formally attributed the SolarWinds Compromise to Russia’s Foreign Intelligence Service (SVR). MITRE’s data notes the US government assessed that of the approximately 18,000 affected public and private-sector customers of SolarWinds’ Orion product, a much smaller number were actually compromised by follow-on APT29 activity.
Timeline
Per MITRE ATT&CK’s ingested data, this campaign’s documented activity window runs from August 2019 to January 2021 (discovery in mid-December 2020, with the formal SVR attribution following in April 2021, slightly after the campaign’s documented end date).
Actors and malware involved (per MITRE ATT&CK relationship data)
MITRE ATT&CK attributes this campaign to APT29. Malware documented in this campaign includes SUNBURST and SUNSPOT (the Orion build-process implants), TEARDROP, Raindrop, GoldMax, GoldFinder, Sibot, TrailBlazer, AdFind, and Cobalt Strike, alongside Mimikatz for credential access.
What we don’t have
We have no independent telemetry or IOC data beyond MITRE’s STIX bundle. MITRE’s ~18,000-customer figure is the US government’s own assessment of Orion’s install base, not a count of confirmed compromises — MITRE’s data explicitly notes the actually-compromised subset was much smaller, and we don’t have that precise number in our ingested data.
Frequently Asked Questions
What was the SolarWinds Compromise? A supply-chain attack, per MITRE ATT&CK, in which APT29 injected malicious code (SUNBURST) into SolarWinds’ Orion software build process, discovered in December 2020 and formally attributed to Russia’s SVR in April 2021.
How many organizations were affected? Per MITRE’s data, approximately 18,000 SolarWinds Orion customers received the compromised software update, though the US government assessed a much smaller number were actually compromised by follow-on attacker activity.
Who was behind the SolarWinds Compromise? APT29, per formal April 2021 attribution by the US and UK governments cited in MITRE ATT&CK’s campaign profile.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0024, aggregated September 11, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.