Netskope Threat Labs

SUPERNOVA

ATP Sandbox Adv. HeuristicsAV

SUPERNOVA is an in-memory web shell written in .NET C sharp, discovered in November 2020 during the investigation into APT29's SolarWinds operation, but researchers determined it unrelated to that operation. Subsequent analysis suggests the China based SPIRAL group may have used it.

First seen
March 2022
Last seen
October 2026
SuperNovaSupernova

5 techniques across 4 tactics.

TA0002 Execution

  • T1203Exploitation for Client Execution

TA0003 Persistence

TA0005 Stealth

TA0011 Command and Control

Alert Name
ByteCode-MSIL.Backdoor.Supernova
ByteCode-MSIL.Trojan.SuperNova
Trojan.Supernova.A
Trojan.Supernova.D