The SolarWinds Orion SUNBURST Backdoor

Updated 5 Oct 2026 · Incident date 24 Mar 2020 · vendor binary

PackageSolarWinds Orion Platform 2019.4 HF4 -> 2019.4 HF5 (build 2019.4.5220.20574), through 2020.2.1 HF1
FileSolarWinds.Orion.Core.BusinessLayer.dll

The SUNBURST backdoor lived in SolarWinds.Orion.Core.BusinessLayer.dll, a signed file in SolarWinds Orion Platform updates from March to May 2020. The first bad build is 2019.4 HF5, build 2019.4.5220.20574. Orion 2020.2.1 HF1 is the fixed release that Mandiant names.

The backdoor waited 12 to 14 days, then contacted a server and ran commands.

Major incident. SolarWinds received $50 million in insurance proceeds during 2022 and 2023 for its 2020 cyberattack. This excludes customer losses. Impact source

What happened

Attackers inserted code into the Orion build process. The result was a digitally signed DLL that SolarWinds distributed in a normal update package. Microsoft reports that the code sat in the RefreshInternal method and that the backdoor has almost 4,000 lines. It also says the attackers tested the insertion as early as October 2019 with empty classes.

Mandiant describes the behavior:

The backdoor supports commands such as running a process, listing and writing files, reading and writing registry values, and rebooting. Mandiant says the attackers later used a memory-only dropper named TEARDROP and Cobalt Strike BEACON on selected victims. Mandiant tracks the actor as UNC2452.

Affected versions

Orion Platform builds from 2019.4 HF5 through 2020.2.1, before the fix, are affected. Mandiant names the trojanized package CORE-2019.4.5220.20574-SolarWinds-Core-v2019.4.5220-Hotfix5.msp.

Indicators of compromise

How to check

Hash the DLL on every Orion server and compare it with the MD5 above.

Get-ChildItem -Path "C:\Program Files (x86)\SolarWinds" -Recurse -Filter SolarWinds.Orion.Core.BusinessLayer.dll | Get-FileHash -Algorithm MD5

Then search DNS logs for the command domain.

Select-String -Path .\dns.log -Pattern "avsvmcloud"

Check the Orion version in the web console under Settings, then Details, then Orion Core.

What to do now

  1. Isolate Orion servers and block their internet egress.
  2. Preserve forensic images and logs, then upgrade to Orion 2020.2.1 HF1 or later.
  3. Restrict the servers' connection to Tier 0 assets and limit local admin scope.
  4. Change the passwords of accounts that have access to the Orion servers.
  5. Review network device configurations for unauthorized changes.
  6. Run the Mandiant YARA rules on affected hosts.

Vigilance compares the version you trust with a new one and reports the file that gained a new capability. Here one existing DLL gained network, download and execution behavior. See all attacks.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old SolarWinds-prev --new SolarWinds-current
files scanned: 64

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    SolarWinds.Orion.Core.BusinessLayer.dll
           It now downloads from the internet. It did not before.

Frequently asked questions

Which SolarWinds Orion versions had the SUNBURST backdoor?

Builds from 2019.4 HF5 (2019.4.5220.20574) through 2020.2.1, before the fix. Mandiant recommends upgrading to 2020.2.1 HF1.

How do I check for SUNBURST?

Hash SolarWinds.Orion.Core.BusinessLayer.dll and compare it with the published MD5 b91ce2fa41029f6955bff20079468448. Also search DNS logs for avsvmcloud.com.

Sources

  1. cloud.google.com/blog/topics/threat-intelligence/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor
  2. microsoft.com/en-us/security/blog/2020/12/18/analyzing-solorigate-the-compromised-dll-file-that-started-a-sophisticated-cyberattack-and-how-microsoft-defender-helps-protect/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free