Malware
SUNBURST
aka Solorigate
FireEye describes SUNBURST as a trojanized SolarWinds digitally-signed component of the Orion software framework that contains a backdoor that communicates via HTTP to third party servers.
SUNBURST, also known as Solorigate, is a Windows malware family operated by APT 29 and UNC2452.
Background
FireEye characterizes SUNBURST as a digitally-signed, trojanized component of the SolarWinds Orion software framework that embeds a backdoor communicating over HTTP with third-party servers. Following an initial dormancy of up to two weeks, it relies on a DGA to produce particular subdomains under a fixed C&C domain. The backdoor fetches and runs commands that include transferring and executing files, profiling the system, rebooting the host, and disabling system services. Traffic to the malicious domains is crafted to resemble legitimate SolarWinds API calls using the Orion Improvement Program (OIP) protocol. To stay hidden, the backdoor consults several obfuscated blocklists that flag forensic and anti-virus tools present as processes, services, and drivers. Several trojanized updates were signed between March and May 2020 and published to the SolarWinds updates website.
Source: Malpedia (Fraunhofer FKIE).