{
  "id": "case-solarwinds-apt29",
  "slug": "solarwinds-orion-supply-chain-compromise",
  "title": "SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)",
  "summary": "Sophisticated software supply chain compromise by the Russian Foreign Intelligence Service (SVR), inserting the SUNBURST backdoor into updates of SolarWinds Orion software and compromising multiple federal agencies.",
  "case_number": "SEC CIK 0001739942",
  "court": "U.S. District Court for the Southern District of New York",
  "district": "S.D.N.Y.",
  "country": "United States",
  "opened_at": "2020-12-13",
  "status": "alleged",
  "victim_sector": "Information Technology, Defense, Federal Government, Telecommunications",
  "victim_country": "United States, United Kingdom, Canada, European Union",
  "loss_amount_usd": 200000000,
  "loss_amount_note": "Multi-hundred million dollar investigation and incident remediation costs across the Department of Homeland Security, Treasury, and Fortune 500 firms.",
  "first_seen_at": "2019-09-04T00:00:00Z",
  "last_updated_at": "2026-09-18T18:00:00Z",
  "actor_slug": "apt29",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Adversaries inserted malicious source code (SUNBURST) into legitimate SolarWinds Orion build pipelines, resulting in digitally signed malicious updates.",
      "evidence_locator": "CISA Advisory AA20-352A \u00b6 8",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA20-352A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1071.001",
      "evidence_excerpt": "The backdoor communicated with adversary command and control servers via HTTP requests designed to mimic legitimate SolarWinds Orion communication protocols.",
      "evidence_locator": "CISA Advisory AA20-352A \u00b6 14",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Technical Analysis",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a",
      "technique_name": "Web Protocols",
      "tactic": "Command and Control"
    },
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Adversaries abused stolen SAML signing keys to forge authentication tokens and bypass multifactor authentication in victim Microsoft 365 environments.",
      "evidence_locator": "CISA Emergency Directive 21-01",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Emergency Directive 21-01",
      "source_url": "https://www.cisa.gov/news-events/directives/ed-21-01-mitigate-solarwinds-orion-code-compromise",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1132",
      "evidence_excerpt": "SUNBURST encoded stolen domain information into custom Base64-like strings disguised as GUID query parameters.",
      "evidence_locator": "CISA Advisory AA20-352A \u00b6 16",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA20-352A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a",
      "technique_name": "Data Encoding",
      "tactic": "Command and Control"
    },
    {
      "technique_id": "T1036",
      "evidence_excerpt": "The TEARDROP memory-only dropper masqueraded as legitimate Windows system services to maintain persistent memory presence.",
      "evidence_locator": "CISA Advisory AA20-352A \u00b6 21",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA20-352A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a",
      "technique_name": "Masquerading",
      "tactic": "Defense Evasion"
    }
  ],
  "events": [
    {
      "event_type": "disclosure",
      "event_date": "2020-12-14",
      "description": "SolarWinds files Form 8-K Item 8.01 disclosing cyber incident involving Orion software compromise."
    },
    {
      "event_type": "advisory",
      "event_date": "2020-12-17",
      "description": "CISA issues Alert AA20-352A: Advanced Persistent Threat Compromise of Government Agencies."
    },
    {
      "event_type": "sanction",
      "event_date": "2021-04-15",
      "description": "White House and Treasury formally attribute operation to Russian SVR and sanction associated IT contractors."
    }
  ]
}