Secureworks: a second threat actor targeting SolarWinds flaws, by adding backdoors via Orion bugs, has characteristics that suggest the group is based in China
New Evidence Suggests Potential Links to Chinese Hackers Sean Lyngaas / CyberScoop : China-linked hackers exploited SolarWinds software in 2020 breach, researchers say Pierluigi Paganini / Security Affairs : SUPERNOVA backdoor that emerged after SolarWinds hack is likely linked to Chinese actors Charlie Osborne / ZDNet : Supernova malware clues link Chinese threat group Spiral to SolarWinds server hacks Tweets: Catalin Cimpanu / @campuscodi : These attacks took place in parallel and where unrelated to the broader SolarWinds supply chain attack. The same group was also exploiting Zoho ManageEngine servers. Secureworks didn't say if this was an APT or a classic cybercrime group Report here: https://www.secureworks.com/ ... https://twitter.com/... Catalin Cimpanu / @campuscodi : NEW: In a report today, Secureworks has linked the second threat actor exploiting SolarWinds Orion servers to a Chinese threat actor it calls Spiral This is the group who exploited CVE-2020-10148 (Orion API auth bypass) to install the SUPERNOVA web shell https://therecord.media/... https://twitter.com/...
Context & Ripple Effects
When researchers flagged in December 2020 that a second hacking group was inside SolarWinds systems with malware unrelated to Sunburst, the open question was who that actor was and how far its activity reached. Secureworks now answers part of it: the group it tracks as Spiral exploited an Orion API auth bypass (CVE-2020-10148) to plant the SUPERNOVA web shell on Orion servers, in parallel with separate Zoho ManageEngine intrusions.
The attribution matters because it folds into an emerging picture of Chinese activity against SolarWinds' own product line — distinct from the Russian-attributed supply chain operation — including the earlier intrusion into a USDA payroll agency via another SolarWinds bug and Microsoft's later DEV-0322 attribution for Serv-U exploits. Spiral's China-based characteristics make SolarWinds software a product two major state-linked campaigns converged on.
First-order effects
- Organizations running SolarWinds Orion and Zoho ManageEngine servers must now treat CVE-2020-10148 as an actively exploited vector tied to a named actor, not just a patch-and-move-on vulnerability.
- Incident responders gain a tracking handle — Spiral — letting them fold SUPERNOVA web shell detections into known Chinese tradecraft rather than investigating each Orion compromise as isolated.
Second-order effects
- SolarWinds' remediation burden compounds: the company is simultaneously managing fallout from the Sunburst supply chain attack and repeated exploitation of its own management products by a second nation-state actor, pressuring its security posture and customer trust.
- Other enterprise management-software vendors like Zoho face the same exposure profile — their admin tooling is demonstrably in scope for the same actors, forcing parallel hardening and disclosure work.
Third-order effects
- If the pattern holds — multiple nation-state groups independently exploiting the same IT-management platforms without coordinating, echoing the finding that three Chinese espionage groups hit Southeast Asian telcos separately — shared infrastructure software becomes a de facto common attack surface requiring vendor-level, not just customer-level, defense.
- Independent attributions of parallel campaigns push defenders toward hunting across overlapping exploit surfaces rather than single-campaign narratives, reshaping how breach investigations scope 'who else was here' questions.
The trend: Enterprise network-management software is becoming contested ground where multiple nation-state espionage programs operate independently against the same vendors' products.