/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

CrowdStrike details Sunspot, a newly discovered malware strain that was the first to be used in the SolarWinds supply chain attack, beginning in September 2019

ZDNet Catalin Cimpanu

Context & Ripple Effects

CrowdStrike's Sunspot disclosure fills in the earliest missing piece of the SolarWinds timeline: the malware that tampered with Orion builds was running from September 2019, predating the October 2019 test run of a backdoor-free version that sources had already surfaced. The disclosure also sharpens the picture of a crowded crime scene — research firms had flagged a second hacking group inside SolarWinds systems using different code, which Secureworks later tied to characteristics suggesting a China-based actor via backdoors added through Orion bugs.

Why it matters now: with Microsoft reporting that Russia-backed Nobelium kept breaching IT providers long after the 2020 disclosure, understanding how the original intrusion was staged at the build level is what lets defenders hunt for the technique rather than just its artifacts.

First-order effects

  • Incident response teams and SolarWinds customers gain a concrete detection target: Sunspot's build-pipeline tampering is a distinct artifact from the Sunburst backdoor, so network audits tuned only to the backdoor's behavior miss the earlier stage.
  • CrowdStrike's naming of the strain gives the industry shared vocabulary for the intrusion's opening move, feeding directly into tools like FireEye's free audit utility for SolarWinds hacker techniques.

Second-order effects

  • Attribution work accelerates and fragments: as CrowdStrike maps the Russian operation's tooling, rivals' findings about the separate actor exploiting Orion flaws force analysts to keep two intrusions analytically distinct rather than folding them into one narrative.
  • Software vendors face pressure to harden their own build systems, since the demonstrated attack path — compromising the pipeline rather than the product — applies to any vendor shipping signed updates to hundreds of thousands of customers.

Third-order effects

  • If the pattern holds, software build pipelines become a primary espionage target, with nation-state groups treating vendor update infrastructure as standing access rather than a one-off breach — exactly the model Microsoft describes in Nobelium's continued provider breaches.
  • Regulatory scrutiny of vendor security practices follows the technical story downstream, as seen in the SEC's later notices to SolarWinds executives citing the 2020 hack, pushing disclosure and build-integrity expectations onto public software companies.

The trend: Nation-state attackers are moving upstream into software build pipelines, turning the vendors who ship trusted updates into the perimeter itself.

Discussion

  • @malwaretechblog @malwaretechblog on x
    Pretty cool. SolarWinds hackers put malware on the build systems which would hijack the compile process and quietly insert the backdoor into the code every time the devs compiled it. https://www.crowdstrike.com/ ...
  • @crowdstrike @crowdstrike on x
    The @CrowdStrike Threat Intelligence team has been helping to investigate the Sunburst attack. This blog post outlines what we've found: https://www.crowdstrike.com/ ... #sunburst #threatintelligence https://twitter.com/...