CrowdStrike details Sunspot, a newly discovered malware strain that was the first to be used in the SolarWinds supply chain attack, beginning in September 2019
Context & Ripple Effects
CrowdStrike's Sunspot disclosure fills in the earliest missing piece of the SolarWinds timeline: the malware that tampered with Orion builds was running from September 2019, predating the October 2019 test run of a backdoor-free version that sources had already surfaced. The disclosure also sharpens the picture of a crowded crime scene — research firms had flagged a second hacking group inside SolarWinds systems using different code, which Secureworks later tied to characteristics suggesting a China-based actor via backdoors added through Orion bugs.
Why it matters now: with Microsoft reporting that Russia-backed Nobelium kept breaching IT providers long after the 2020 disclosure, understanding how the original intrusion was staged at the build level is what lets defenders hunt for the technique rather than just its artifacts.
First-order effects
- Incident response teams and SolarWinds customers gain a concrete detection target: Sunspot's build-pipeline tampering is a distinct artifact from the Sunburst backdoor, so network audits tuned only to the backdoor's behavior miss the earlier stage.
- CrowdStrike's naming of the strain gives the industry shared vocabulary for the intrusion's opening move, feeding directly into tools like FireEye's free audit utility for SolarWinds hacker techniques.
Second-order effects
- Attribution work accelerates and fragments: as CrowdStrike maps the Russian operation's tooling, rivals' findings about the separate actor exploiting Orion flaws force analysts to keep two intrusions analytically distinct rather than folding them into one narrative.
- Software vendors face pressure to harden their own build systems, since the demonstrated attack path — compromising the pipeline rather than the product — applies to any vendor shipping signed updates to hundreds of thousands of customers.
Third-order effects
- If the pattern holds, software build pipelines become a primary espionage target, with nation-state groups treating vendor update infrastructure as standing access rather than a one-off breach — exactly the model Microsoft describes in Nobelium's continued provider breaches.
- Regulatory scrutiny of vendor security practices follows the technical story downstream, as seen in the SEC's later notices to SolarWinds executives citing the 2020 hack, pushing disclosure and build-integrity expectations onto public software companies.
The trend: Nation-state attackers are moving upstream into software build pipelines, turning the vendors who ship trusted updates into the perimeter itself.