Supply Chain Incident

SolarWinds Orion software build compromise

Attackers compromised the SolarWinds Orion build process and inserted the SUNBURST backdoor into signed software updates delivered to customers.

ConfidenceHigh
Evidence LevelVendor
Attack StageBuild Compromise
Source Artifact DivergenceUnknown
Attribution ConfidenceConfirmed

Executive Summary

Timeline

  1. Compromised Orion builds precede disclosure

    The corpus records activity beginning months before public disclosure and models the abuse through the SolarWinds Orion build and update channel.

  2. CISA advisory documents the campaign

    CISA published an advisory describing compromise of government agencies, critical infrastructure, and private-sector organizations.

Attack Chain

  1. Build-system compromise

    The attacker-controlled change occurred in the Orion build path, making the vendor build system the core supply-chain primitive.

  2. Signed update distribution

    Trojanized Orion artifacts reached customers through the signed software installer and update channel recorded in the corpus.

  3. Downstream customer compromise

    The impact model includes downstream customer compromise because the trusted vendor update path carried the backdoor to customer environments.

Affected Ecosystem

Defensive Lessons

Detection Notes

Open Questions

Affected Packages

No structured records.

Affected Releases

No structured records.

Repositories

No structured records.

Organizations

Maintainers

No structured records.

Threat Actors

Campaigns

Build Systems

  • SolarWinds Orion build system

Distribution Channels

  • Signed software installer/update channel

Compromised Accounts

No structured records.

Connected Entities

Attribution Evidence

References