/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Security research firms: a second hacking group targeted SolarWinds systems with different malware, likely unrelated to “Sunburst” code targeting the Orion app

ZDNet Catalin Cimpanu

Context & Ripple Effects

The Sunburst disclosure turned SolarWinds into the most examined codebase in security research, and the scrutiny is paying off: CrowdStrike's Sunspot analysis traced the original supply chain implant back to September 2019, while sources described an October 2019 test run of a backdoor-free variant. Now researchers report a second, distinct malware family inside SolarWinds systems — likely unrelated to Sunburst.

That second actor was later characterized by Secureworks as exploiting Orion flaws to add backdoors, with traits pointing to a China-based group (Secureworks' attribution). The distinction matters because it means SolarWinds' build pipeline and Orion product were contested ground for at least two separate operations at once.

First-order effects

  • SolarWinds' incident response scope doubles overnight: customers and auditors must now hunt for two unrelated malware families in Orion environments, not just Sunburst indicators.
  • The second group's activity extends beyond SolarWinds itself — Malwarebytes disclosed it was breached by the same crew via Azure and Office 365 exploits (Malwarebytes' disclosure), though only a subset of internal emails was accessed.

Second-order effects

  • Detection vendors race to productize the findings — FireEye shipped a free auditing tool checking for known SolarWinds-hacker techniques, turning incident response into a distribution channel.
  • Cloud identity surfaces become the shared battleground: if the second actor reached Malwarebytes through Azure and Office 365 rather than Orion, SaaS tenants adjacent to any SolarWinds-linked victim face pressure to re-audit federation and email access.

Third-order effects

  • Software vendors' build and update infrastructure is now treated as multi-tenant espionage terrain, where several nation-state actors can operate independently against the same target — forcing the industry to assume compromise is concurrent, not sequential.
  • Attribution work fragments the single-narrative breach story into overlapping campaigns, pushing regulators and buyers toward demanding continuous third-party code integrity assurance rather than point-in-time attestations.

The trend: Supply chain compromises of software vendors are evolving from single sophisticated operations into shared infrastructure that multiple state-aligned groups exploit independently.

Discussion

  • @nytimes @nytimes on x
    As the U.S. government confronts a vast cyberattack believed to be from Russia, the Trump administration is being criticized over a proposal to split the leadership of the National Security Agency from the United States Cyber Command. https://www.nytimes.com/...
  • @baris @baris on x
    Another payload, SuperNova, discovered in recent attacks might be performed by a different bad actor. Sunburst is more sophisticated with Solarwinds' digital certificate. This is not. Maybe be it's another nation-state, maybe it's a hacker group. 🤷🏻‍♂ ️ https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    The Supernova webshell and CosmicGale PS script might be related to exploitation of public-facing SolarWinds Orion installs using CVE-2019-8917 (https://t.co/...) See here: https://github.com/... https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    Some SolarWinds systems were found compromised with malware named Supernova and CosmicGale, unrelated to the recent supply chain attack. Security researchers believe this malware is the result of a second hacking group targeting SolarWinds systems https://www.zdnet.com/... https:…