Campaign · all campaigns
SolarWinds CompromiseC0024 state
🇷🇺 RU · SVR
aka SolarWinds Compromise
Run by APT29
Last updated: 2026-08-22
About this actor
The [SolarWinds Compromise](https://attack.mitre.org/campaigns/C0024) was a sophisticated supply chain cyber operation conducted by [APT29](https://attack.mitre.org/groups/G0016) that was discovered in mid-December 2020. [APT29](https://attack.mitre.org/groups/G0016) used customized malware to inject malicious code into the SolarWinds Orion software build process that was later distributed through a normal software update; they also used password spraying, token theft, API abuse, spear phishing, and other supply chain attacks to compromise user accounts and leverage their associated access. Victims of this campaign included government, consulting, technology, telecom, and other organizations in North America, Europe, Asia, and the Middle East. This activity has been labled the StellarParticle campaign in industry reporting.(Citation: CrowdStrike StellarParticle January 2022) Industry reporting also initially referred to the actors involved in this campaign as UNC2452, NOBELIUM, Dark Halo, and SolarStorm.(Citation: SolarWinds Advisory Dec 2020)(Citation: SolarWinds Sunburst Sunspot Update January 2021)(Citation: FireEye SUNBURST Backdoor December 2020)(Citation: Volexity SolarWinds)(Citation: CrowdStrike StellarParticle January 2022)(Citation: Unit 42 SolarStorm December 2020)(Citation: Microsoft Analyzing Solorigate Dec 2020)(Citation: Microsoft Internal Solorigate Investigation Blog) In April 2021, the US and UK governments attributed the [SolarWinds Compromise](https://attack.mitre.org/campaigns/C0024) to Russia's Foreign Intelligence Service (SVR); public statements included citations to [APT29](https://attack.mitre.org/groups/G0016), Cozy Bear, and The Dukes.(Citation: NSA Joint Advisory SVR SolarWinds April 2021)(Citation: UK NSCS Russia SolarWinds April 2021)(Citation: Mandiant UNC2452 APT29 April 2022) The US government assessed that of the approximately 18,000 affected public and private sector customers of Solar Winds’ Orion product, a much smaller number
Source: MITRE ATT&CK
How we know this
- Data origin
- MITRE ATT&CK campaign Imported from the MITRE ATT&CK STIX bundle as a campaign object.
- Techniques
- MITRE ATT&CK STIX mappings — 96 ATT&CK techniques on file.
- Named victims
- 1 extracted from reporting.
Thin data: Only one named victim is on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2026 — 1 CVE published
- 2021 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2020-8554 | 6.5 | 6.3 | 0.3120 | 2021-01-21 | see CVE |
CVE-2026-20929 | 5.9 | 7.5 | 0.0116 | 2026-01-13 | see CVE |
T1003OS Credential Dumping ↗T1003.006DCSync ↗T1005Data from Local System ↗T1016System Network Configuration Discovery ↗T1016.001Internet Connection Discovery ↗T1018Remote System Discovery ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1021.002SMB/Windows Admin Shares ↗T1021.006Windows Remote Management ↗T1036Masquerading ↗T1036.004Masquerade Task or Service ↗T1036.005Match Legitimate Resource Name or Location ↗T1047Windows Management Instrumentation ↗T1048Exfiltration Over Alternative Protocol ↗T1048.002Exfiltration Over Asymmetric Encrypted Non-C2 Protocol ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1059.005Visual Basic ↗T1069Permission Groups Discovery ↗T1069.002Domain Groups ↗T1070Indicator Removal ↗T1070.004File Deletion ↗T1070.006Timestomp ↗T1070.008Clear Mailbox Data ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1074Data Staged ↗T1074.002Remote Data Staging ↗T1078Valid Accounts ↗T1078.002Domain Accounts ↗T1078.003Local Accounts ↗T1078.004Cloud Accounts ↗T1083File and Directory Discovery ↗T1087Account Discovery ↗T1087.002Domain Account ↗T1090Proxy ↗T1090.001Internal Proxy ↗T1098Account Manipulation ↗T1098.001Additional Cloud Credentials ↗T1098.002Additional Email Delegate Permissions ↗T1098.003Additional Cloud Roles ↗T1098.005Device Registration ↗T1105Ingress Tool Transfer ↗T1114Email Collection ↗T1114.002Remote Email Collection ↗T1133External Remote Services ↗T1140Deobfuscate/Decode Files or Information ↗T1190Exploit Public-Facing Application ↗T1195Supply Chain Compromise ↗T1195.002Compromise Software Supply Chain ↗T1199Trusted Relationship ↗T1213Data from Information Repositories ↗T1213.003Code Repositories ↗T1218System Binary Proxy Execution ↗T1218.011Rundll32 ↗T1482Domain Trust Discovery ↗T1484Domain or Tenant Policy Modification ↗T1484.002Trust Modification ↗T1539Steal Web Session Cookie ↗T1546Event Triggered Execution ↗T1546.003Windows Management Instrumentation Event Subscription ↗T1550Use Alternate Authentication Material ↗T1550.001Application Access Token ↗T1550.004Web Session Cookie ↗T1552Unsecured Credentials ↗T1552.004Private Keys ↗T1553Subvert Trust Controls ↗T1553.002Code Signing ↗T1555Credentials from Password Stores ↗T1555.003Credentials from Web Browsers ↗T1558Steal or Forge Kerberos Tickets ↗T1558.003Kerberoasting ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1568Dynamic Resolution ↗T1583Acquire Infrastructure ↗T1583.001Domains ↗T1584Compromise Infrastructure ↗T1584.001Domains ↗T1587Develop Capabilities ↗T1587.001Malware ↗T1589Gather Victim Identity Information ↗T1589.001Credentials ↗T1606Forge Web Credentials ↗T1606.001Web Cookies ↗T1606.002SAML Tokens ↗T1665Hide Infrastructure ↗T1680Local Storage Discovery ↗T1685Disable or Modify Tools ↗T1685.001Disable or Modify Windows Event Log ↗T1686Disable or Modify System Firewall ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 59 / 96 | 61% |
CM-6 | 58 / 96 | 60% |
AC-3 | 55 / 96 | 57% |
AC-6 | 52 / 96 | 54% |
AC-2 | 50 / 96 | 52% |
CM-2 | 46 / 96 | 48% |
CM-7 | 39 / 96 | 41% |
IA-2 | 38 / 96 | 40% |
CA-7 | 37 / 96 | 39% |
AC-5 | 36 / 96 | 38% |
CM-5 | 34 / 96 | 35% |
SI-3 | 32 / 96 | 33% |
SI-7 | 32 / 96 | 33% |
AC-4 | 26 / 96 | 27% |
SC-7 | 24 / 96 | 25% |
Co-occurring actors
- APT29 2 shared CVEs
- Ajax Security Team 1 shared CVEs
- APT38 1 shared CVEs
- Sandworm Team 1 shared CVEs
- Tonto Team 1 shared CVEs
- GOLD SOUTHFIELD 1 shared CVEs
- Scattered Spider 1 shared CVEs
- OilRig 1 shared CVEs
- Indrik Spider 1 shared CVEs
- Mustang Panda 1 shared CVEs
Similar actors
Similar TTPs
- Operation Wocao 0.35
- Chimera 0.31
- FIN13 0.31
- Magic Hound 0.30
- APT41 0.29
Active in same years
- SharePoint ToolShell Exploitation 2.00
- APT29 2.00
- Leviathan 2.00
- C0018 1.00
- Operation Dream Job 1.00
Same nation-state
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00