Security research firms: a second hacking group targeted SolarWinds systems with different malware, likely unrelated to “Sunburst” code targeting the Orion app
Context & Ripple Effects
The Sunburst disclosure turned SolarWinds into the most examined codebase in security research, and the scrutiny is paying off: CrowdStrike's Sunspot analysis traced the original supply chain implant back to September 2019, while sources described an October 2019 test run of a backdoor-free variant. Now researchers report a second, distinct malware family inside SolarWinds systems — likely unrelated to Sunburst.
That second actor was later characterized by Secureworks as exploiting Orion flaws to add backdoors, with traits pointing to a China-based group (Secureworks' attribution). The distinction matters because it means SolarWinds' build pipeline and Orion product were contested ground for at least two separate operations at once.
First-order effects
- SolarWinds' incident response scope doubles overnight: customers and auditors must now hunt for two unrelated malware families in Orion environments, not just Sunburst indicators.
- The second group's activity extends beyond SolarWinds itself — Malwarebytes disclosed it was breached by the same crew via Azure and Office 365 exploits (Malwarebytes' disclosure), though only a subset of internal emails was accessed.
Second-order effects
- Detection vendors race to productize the findings — FireEye shipped a free auditing tool checking for known SolarWinds-hacker techniques, turning incident response into a distribution channel.
- Cloud identity surfaces become the shared battleground: if the second actor reached Malwarebytes through Azure and Office 365 rather than Orion, SaaS tenants adjacent to any SolarWinds-linked victim face pressure to re-audit federation and email access.
Third-order effects
- Software vendors' build and update infrastructure is now treated as multi-tenant espionage terrain, where several nation-state actors can operate independently against the same target — forcing the industry to assume compromise is concurrent, not sequential.
- Attribution work fragments the single-narrative breach story into overlapping campaigns, pushing regulators and buyers toward demanding continuous third-party code integrity assurance rather than point-in-time attestations.
The trend: Supply chain compromises of software vendors are evolving from single sophisticated operations into shared infrastructure that multiple state-aligned groups exploit independently.