Netskope Threat Labs

SUNBURST

ATP Sandbox Adv. HeuristicsAVNetskope IPS

SUNBURST is a trojanized DLL designed to fit within the SolarWinds Orion software update framework, used by APT29 since at least February 2020.

First seen
March 2022
Last seen
October 2026
SolorigateSunBurstSunburst

36 techniques across 7 tactics.

TA0002 Execution

  • T1047Windows Management Instrumentation
  • T1059Command and Scripting Interpreter

TA0004 Privilege Escalation

  • T1546Event Triggered Execution
    • T1546.012Image File Execution Options Injection

TA0005 Stealth

TA0007 Discovery

  • T1007System Service Discovery
  • T1012Query Registry
  • T1016System Network Configuration Discovery
  • T1033System Owner/User Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1124System Time Discovery
  • T1518Software Discovery

TA0009 Collection

  • T1005Data from Local System

TA0011 Command and Control

TA0112 Defense Impairment

Alert Name
Binary.Backdoor.Sunburst
ByteCode-MSIL.Backdoor.Sunburst
ByteCode-MSIL.Backdoor.SunBurst
ByteCode-MSIL.Trojan.Solorigate
ByteCode-MSIL.Trojan.Sunburst
ByteCode-MSIL.Trojan.SunBurst
Trojan.Sunburst.A
Trojan.Sunburst.B
Trojan.Sunburst.C
Trojan.Sunburst.D