Supply Chain Cyber Attacks: How SolarWinds Changed Everything
Published by the 0g0 research team
In December 2020, the discovery of the SolarWinds compromise fundamentally changed how security professionals, government agencies, and executives think about supply chain cyber risk. An attacker — subsequently attributed to the Russian Foreign Intelligence Service (SVR) — had compromised the build system of SolarWinds, a widely used IT management software company, and inserted malicious code into software updates distributed to 18,000 customers.
Among those customers: the US Treasury, the Department of Homeland Security, the Department of State, the Department of Defense, the National Nuclear Security Administration, and 425 companies in the Fortune 500. The malicious code — SUNBURST — operated undetected for nine months, providing the attackers with persistent access to the networks of organisations that had installed the compromised update.
The SolarWinds attack was not a technical failure in the conventional sense. The affected organisations had cybersecurity programmes. They had firewalls, endpoint protection, and monitoring. What they did not have was a way to detect that trusted, legitimate software updates from a trusted, legitimate vendor were carrying malicious code.
The Supply Chain Attack Vector
Supply chain attacks exploit the trust relationships between organisations and their vendors, suppliers, and service providers. Rather than attacking a target directly — which requires overcoming that organisation's defences — attackers compromise a supplier whose software, hardware, or services are trusted and deployed within the target environment.
This approach has several advantages from the attacker's perspective:
Scale: A single successful compromise of a widely-used software product reaches thousands of targets simultaneously. The attacker who compromises one software vendor can access 18,000 organisations.
Trust bypass: Security controls are designed to detect and block untrusted activity. Software updates from trusted vendors are, by definition, trusted. Traditional security tools do not inspect legitimate software updates for malicious code — creating a blind spot that sophisticated attackers exploit.
Attribution difficulty: Activity conducted through legitimate software channels is harder to attribute and detect. The SUNBURST backdoor operated for nine months before discovery, specifically because it was designed to blend in with legitimate SolarWinds network traffic.
The Scope of Supply Chain Risk
Supply chain risk extends well beyond software companies:
Managed service providers (MSPs): MSPs that provide IT management, monitoring, and support services to multiple clients maintain privileged access to those clients' networks. An MSP compromise — as occurred in the Kaseya VSA attack of 2021 — enables simultaneous access to hundreds of client networks.
Hardware components: Intelligence reports have documented concerns about hardware supply chain compromise, where components are modified before delivery to introduce backdoors or surveillance capabilities at the hardware level.
Open source software: Modern applications are built on vast stacks of open source libraries and components. A compromise of a widely-used open source library — as demonstrated by the XZ Utils backdoor discovered in 2024 — can affect thousands of applications simultaneously.
Cloud providers: Organisations that run their most sensitive workloads in cloud environments are exposed to the security posture of those providers. A compromise of a major cloud provider's infrastructure could affect millions of organisations.
Professional services: Law firms, accounting firms, consultants, and other professional service providers often receive sensitive data and maintain access to client systems. Compromise of these firms provides indirect access to their clients.
What SUNBURST's Design Teaches Us
Analysing the SUNBURST backdoor's design reveals the sophistication of its authors and the deliberate choices made to avoid detection:
A dormant period of up to two weeks before activating, allowing the compromised update to be installed across client networks before any malicious activity began.
Mimicry of legitimate SolarWinds API traffic, making its command-and-control communications indistinguishable from normal software activity to network monitoring tools.
Specific checks to avoid activation in security research environments, including checking for the presence of security tools and known research domain suffixes.
Selective targeting — SUNBURST installed on 18,000 systems, but the attackers chose only a small subset of high-value targets for active exploitation, limiting the risk of detection.
Building Supply Chain Security
The SolarWinds attack prompted a significant reconsideration of how organisations can protect themselves from supply chain risk. Complete elimination of supply chain risk is not feasible — modern organisations are dependent on software, hardware, and services from hundreds of vendors. But meaningful risk reduction is achievable:
Vendor risk assessment: Before deploying vendor software or granting vendor access, assess the vendor's security practices. NIST SP 800-161 (Cybersecurity Supply Chain Risk Management Practices) provides a framework for structured vendor security assessment.
Software bill of materials (SBOM): Understanding what components are in the software you deploy enables faster response when vulnerabilities are discovered in those components. Executive Order 14028 mandated SBOM requirements for software sold to the federal government.
Network segmentation and least privilege: Even if a vendor product is compromised, the damage it can cause is limited by the access privileges granted to it and the network segments it can reach. Software that is isolated to the specific network segment and system access required for its function cannot serve as a pivot to other systems.
Behavioural monitoring: The detection of SUNBURST came ultimately through behavioural analysis — observing that SolarWinds processes were making network connections and taking actions inconsistent with their expected behaviour. Monitoring for anomalous behaviour by trusted applications is a key detection capability.
Privileged access for vendors: Vendor remote access should be time-limited, monitored in real time, recorded, and terminated when not in active use. Vendors should have only the specific access required for their specific function.
Incident response planning for third-party compromise: Organisations should have specific playbooks for responding to compromise of their critical vendors — including the ability to rapidly isolate vendor-connected systems and revoke vendor access.
The Government Response
The SolarWinds attack prompted significant changes in US government cybersecurity policy:
Executive Order 14028 on Improving the Nation's Cybersecurity, issued in May 2021, mandated zero-trust architecture adoption, endpoint detection and response deployment, SBOM requirements for government software procurement, and enhanced logging standards.
CISA established the Joint Cyber Defense Collaborative (JCDC) to improve public-private threat intelligence sharing — recognising that nation-state supply chain attacks affect both government and private sector targets.
NIST published updated guidance on supply chain risk management, software security, and secure software development practices.
The Bottom Line
SolarWinds demonstrated that even well-resourced, security-aware organisations can be comprehensively compromised through their supply chains. The response is not to abandon software vendors and managed service providers — that is not operationally feasible — but to implement the layered controls that limit what a compromised vendor can access and improve the speed of detection when a compromise occurs.
0g0 Aegis provides supply chain risk assessment and monitoring services that evaluate your critical vendor relationships, identify over-privileged vendor access, and implement monitoring to detect anomalous vendor activity. We also support software security assessment when evaluating new vendor relationships.
Need a product briefing?
Talk about the 0g0 Appliance for your environment — available now. Services are light support as the practice grows.
Request a BriefingFree Assessment Tools
Test your own security posture with our free tools — no account required.
Explore free toolsProtect your organisation
Request a briefing on the 0g0 Appliance. Research is context — the product conversation is next.
Request a Briefing