Skip to content
safemode.space
All incidents
2020-03-01 (approximate)
supply chain compromise
supply chain

SolarWinds Orion build-process compromise and SUNBURST backdoor (2020)

Confidence in this reading:
high

What happened

Between approximately March and June 2020, trojanised updates to the SolarWinds Orion network-management platform were distributed to customers through the vendor's normal update channel. The malicious code was injected into the Orion build process, so the resulting binaries were legitimately signed and delivered by an unsubverted distribution path. FireEye disclosed the compromise on 13 December 2020 while investigating its own breach and named the backdoor SUNBURST; Microsoft tracked it as Solorigate. Affected Orion versions run from 2019.4 through 2020.2.1. SolarWinds estimated that up to 18,000 customers may have installed the compromised component, though MITRE records that a much smaller number were compromised by follow-on activity. MITRE tracks the campaign as C0024, running from August 2019 to January 2021, attributed to APT29, which the US government publicly attributed in April 2021 to Russia's Foreign Intelligence Service. Victims spanned government, consulting, technology, telecom and other organisations in North America, Europe, Asia and the Middle East.

In this corpus because Orion is network-management software deployed in the ground-segment IT of space operators and their suppliers, and because SPARTA cites the compromise against IA-0001.02 for that reason. No source used here names a space-sector victim and this record asserts none. It is carried because it is the reference case for the technique: when a ground-system supply-chain obligation under NIS2 Article 21(2)(d) or the CRA's Annex I requirements needs an illustration, this is the episode with the best-documented mechanism. The distinction worth preserving is why two supply-chain techniques are mapped rather than one. Injection happened at build time, which is IA-0001.01's object, and delivery happened through the vendor's ordinary update channel, which is IA-0001.02's. The delivery path was never subverted because it did not need to be: the signature check every downstream control depends on passed correctly and proved nothing about the code's provenance.

Attack vector

Injection of malicious code into the SolarWinds Orion software build process, producing legitimately signed binaries distributed through the vendor's normal update channel.

Operational impact

Up to 18,000 customers received the compromised component; a much smaller number were compromised by follow-on activity. No space-sector victim is named by any source used here.

Affected segments

supply_chain

Disclosed

2020-12-13

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

  • The trojanised Orion updates delivered SUNBURST, a backdoor that executed on victim systems and from which the operators selected a subset of victims for follow-on tooling. Adversary-introduced executable logic ran on victim systems. Recovered per decision 67: previously rejected only because SPARTA's EX-0010 concerns code executing on the vehicle while Orion runs on enterprise servers. The record's scope caveat is unchanged: no source used here names a space-sector victim of the follow-on intrusions, which is why IA-0007 and IMP-0006 remain rejected.

    https://attack.mitre.org/campaigns/C0024/

  • MITRE states that malicious code was injected into the SolarWinds Orion software build process. IA-0001.01's description names build runners and the tools that transform source into binaries as its object, distinct from the delivery path IA-0001.02 covers. The source names the build process specifically, so the mapping is direct rather than inferred, and separating the two is the episode's substantive lesson: the delivery path was never subverted because it did not need to be.

    https://attack.mitre.org/campaigns/C0024/

  • IA-0001.02's subject is manipulation of software delivered to flight or ground systems, including altering source before build and swapping signed binaries at distribution edges. Trojanised Orion updates reaching up to 18,000 customers through the vendor's own channel is the canonical instance, and it is the technique SPARTA's own bibliography cites against this compromise.

    https://attack.mitre.org/campaigns/C0024/

  • SUNBURST is a code path inserted to provide privileged functionality on cue, embedded in an application and dormant until triggered, which is PER-0002.02's definition. Backdoor is the word both FireEye and MITRE use for it, so the technique is named rather than inferred.

    https://attack.mitre.org/campaigns/C0024/

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

  • Follow-on intrusions certainly reached ground-system-class environments among the victims, but no source used here names a space-sector victim, and mapping it would be asserting one.

  • The compromise ran through a software vendor, but IA-0009.02's subject is an attacker assuming a vendor's operational privileges: remote administration, identity providers, licence servers, authority to command. Here the vendor's product was the carrier and its operational access was not the route. IA-0001.02 covers it correctly.

  • Data theft was the campaign's purpose and occurred at named victims, but no source used here documents it against a space or ground-segment target, which is the scope of this record. Re-evaluated under decision 67 and held, along with IA-0007 above: both fail because no source used here names a space-sector victim, which is an evidentiary gap the ruling does not close.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

  • MITRE

    Tier 1: The maintained campaign entry in MITRE ATT&CK, a framework this platform already treats as canonical for adversary techniques. Curated, versioned and referenced; the closest thing to a settled account of the episode. publication_date is null because the page is a living entry rather than a dated publication.

  • ZDNet · 2020-12-13

    Tier 3: Technology trade press reporting an initial disclosure. Tier 3: contemporaneous and useful for the disclosure date, and superseded on the facts by the vendor and framework write-ups that followed.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.