ADVERTISEMENT

SolarWinds hack: the mystery of one of the biggest cyberattacks ever

SolarWinds headquarters entrance
Pierluigi Paganini
Pierluigi Paganini Contributor
March 12, 2021 Updated: September 28, 2021 8 min read
The Pentagon, State Department, NASA, National Security Agency (NSA), Postal Service, NOAA, Department of Justice, and the Office of the President of the United States are clients of SolarWinds.

How the SolarWinds supply chain was compromised

The attack is still ongoing?

Solorigate supply chain attack analysis report
Image: Solorigate backdoor (Microsoft)
“This work indicates that an Advanced Persistent Threat (APT) actor, likely Russian in origin, is responsible for most or all of the recently discovered, ongoing cyber compromises of both government and non-governmental networks.”
reads the statement.

The initial timeline of the SolarWinds attack

ADVERTISEMENT
Timeline of the SolarWinds attack
Image: Timeline of the attack (Microsoft)

A third malware strain discovered

In January, researchers from cybersecurity firm CrowdStrike discovered a third malware strain, tracked as SUNSPOT, which was involved in the SolarWinds supply chain attack.

An updated timeline of the attack

SolarWinds attack timeline - Overview
“Symantec has seen no evidence to date of Raindrop being delivered directly by Sunburst. Instead, it appears elsewhere on networks where at least one computer has already been compromised by Sunburst.”
reads a blog post by Symantec

Three new malware tools found

To be continued?

ADVERTISEMENT