Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Campaigns/C0024
MITRE ATT&CK Campaign · 2019–2021

SolarWinds Compromise (C0024)

ShareXLinkedInRedditHN

The [SolarWinds Compromise](https://attack.mitre.org/campaigns/C0024) was a sophisticated supply chain cyber operation conducted by [APT29](https://attack.mitre.org/groups/G0016) that was discovered in mid-December 2020. [APT29](https://attack.mitre.org/groups/G0016) used customized malware to inject malicious code into the SolarWinds Orion software build process that was later distributed through a normal software update; they also used password spraying, token theft, API abuse, spear phishing, and other supply chain attacks to compromise user accounts and leverage their associated access. Victims of this campaign included government, consulting, technology, telecom, and other organizations in North America, Europe, Asia, and the Middle East. This activity has been labled the StellarParticle campaign in industry reporting.(Citation: CrowdStrike StellarParticle January 2022) Industry reporting also initially referred to the actors involved in this campaign as UNC2452, NOBELIUM, Dark Halo, and SolarStorm.(Citation: SolarWinds Advisory Dec 2020)(Citation: SolarWinds Sunburst Sunspot Update January 2021)(Citation: FireEye SUNBURST Backdoor December 2020)(Citation: Volexity SolarWinds)(Citation: CrowdStrike StellarParticle January 2022)(Citation: Unit 42 SolarStorm December 2020)(Citation: Microsoft Analyzing Solorigate Dec 2020)(Citation: Microsoft Internal Solorigate Investigation Blog) In April 2021, the US and UK governments attributed the [SolarWinds Compromise](https://attack.mitre.org/campaigns/C0024) to Russia's Foreign Intelligence Service (SVR); public statements included citations to [APT29](https://attack.mitre.org/groups/G0016), Cozy Bear, and The Dukes.(Citation: NSA Joint Advisory SVR SolarWinds April 2021)(Citation: UK NSCS Russia SolarWinds April 2021)(Citation: Mandiant UNC2452 APT29 April 2022) The US government assessed that of the approximately 18,000 affected public and private sector customers of Solar Winds’ Orion product, a much smaller number were compromised by follow-on [APT29](https://attack.mitre.org/groups/G0016) activity on their systems.(Citation: USG Joint Statement SolarWinds January 2021)

▪Attributed groups (1)

G0016APT29

▪Techniques used (71)

T1606.002SAML TokensT1078.004Cloud AccountsT1053.005Scheduled TaskT1087.002Domain AccountT1090.001Internal ProxyT1114.002Remote Email CollectionT1069.002Domain GroupsT1057Process DiscoveryT1584.001DomainsT1016.001Internet Connection DiscoveryT1550Use Alternate Authentication MaterialT1555.003Credentials from Web BrowsersT1078.002Domain AccountsT1036.005Match Legitimate Resource Name or LocationT1665Hide InfrastructureT1098.002Additional Email Delegate PermissionsT1021.001Remote Desktop ProtocolT1213Data from Information RepositoriesT1021.002SMB/Windows Admin SharesT1059.005Visual BasicT1568Dynamic ResolutionT1589.001CredentialsT1552.004Private KeysT1587.001MalwareT1140Deobfuscate/Decode Files or InformationT1005Data from Local SystemT1685.001Disable or Modify Windows Event LogT1083File and Directory DiscoveryT1069Permission Groups DiscoveryT1018Remote System DiscoveryT1021.006Windows Remote ManagementT1550.001Application Access TokenT1098.003Additional Cloud RolesT1553.002Code SigningT1218.011Rundll32T1546.003Windows Management Instrumentation Event SubscriptionT1190Exploit Public-Facing ApplicationT1213.003Code RepositoriesT1686Disable or Modify System FirewallT1059.001PowerShellT1070.004File DeletionT1539Steal Web Session CookieT1606.001Web CookiesT1550.004Web Session CookieT1074.002Remote Data StagingT1098.005Device RegistrationT1133External Remote ServicesT1199Trusted RelationshipT1059.003Windows Command ShellT1070.006TimestompT1558.003KerberoastingT1680Local Storage DiscoveryT1685Disable or Modify ToolsT1105Ingress Tool TransferT1078.003Local AccountsT1070Indicator RemovalT1003.006DCSyncT1036.004Masquerade Task or ServiceT1098.001Additional Cloud CredentialsT1482Domain Trust DiscoveryT1555Credentials from Password StoresT1047Windows Management InstrumentationT1195.002Compromise Software Supply ChainT1070.008Clear Mailbox DataT1484.002Trust ModificationT1583.001DomainsT1087Account DiscoveryT1078Valid AccountsT1560.001Archive via UtilityT1048.002Exfiltration Over Asymmetric Encrypted Non-C2 ProtocolT1071.001Web Protocols

▪Software used (11)

S0588GoldMaxmalwareS0560TEARDROPmalwareS0589SibotmalwareS0597GoldFindermalwareS0002MimikatztoolS0682TrailBlazermalwareS0562SUNSPOTmalwareS0552AdFindtoolS0154Cobalt StrikemalwareS0559SUNBURSTmalwareS0565Raindropmalware
C0024on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.