SUNBURST

S0559

Malware.View on attack.mitre.org

About this malware

SUNBURST is a trojanized DLL designed to fit within the SolarWinds Orion software update framework. It was used by APT29 since at least February 2020.

Techniques used36

Procedure examples36

TechniqueProcedure example
T1001.001
Junk Data

SUNBURST added junk bytes to its C2 over HTTP.

T1001.002
Steganography

SUNBURST C2 data attempted to appear as benign XML related to .NET assemblies or as a faux JSON blob.

T1001.003
Protocol or Service Impersonation

SUNBURST masqueraded its network traffic as the Orion Improvement Program (OIP) protocol.

T1005
Data from Local System

SUNBURST collected information from a compromised host.

T1007
System Service Discovery

SUNBURST collected a list of service names that were hashed using a FNV-1a + XOR algorithm to check against similarly-hashed hardcoded blocklists.

T1012
Query Registry

SUNBURST collected the registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid from compromised hosts.

T1016
System Network Configuration Discovery

SUNBURST collected all network interface MAC addresses that are up and not loopback devices, as well as IP address, DHCP configuration, and domain information.

T1027
Obfuscated Files or Information

SUNBURST obfuscated collected system information using a FNV-1a + XOR algorithm.

T1027.005
Indicator Removal from Tools

SUNBURST source code used generic variable names and pre-obfuscated strings, and was likely sanitized of developer comments before being added to SUNSPOT.

T1027.015
Compression

SUNBURST strings were compressed and encoded in Base64.

T1033
System Owner/User Discovery

SUNBURST collected the username from a compromised host.

T1036.005
Match Legitimate Resource Name or Location

SUNBURST created VBScripts that were named after existing services or folders to blend into legitimate activities.

T1047
Windows Management Instrumentation

SUNBURST used the WMI query Select * From Win32_SystemDriver to retrieve a driver listing.

T1057
Process Discovery

SUNBURST collected a list of process names that were hashed using a FNV-1a + XOR algorithm to check against similarly-hashed hardcoded blocklists.

T1059.005
Visual Basic

SUNBURST used VBScripts to initiate the execution of payloads.

View all 36 procedure examples

Groups that use it1

Campaigns1

References2

  1. Microsoft Deep Dive Solorigate January 2021 Open source
    MSTIC, CDOC, 365 Defender Research Team. (2021, January 20). Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop . Retrieved January 22, 2021.
  2. SolarWinds Sunburst Sunspot Update January 2021 Open source
    Sudhakar Ramakrishna . (2021, January 11). New Findings From Our Investigation of SUNBURST. Retrieved January 13, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.