The Most Dangerous Hack You'll Ever Study
They didn't break in through a phishing email.
They didn't exploit a known vulnerability. They didn't trigger a single alert across 18,000 organizations — including the US Treasury, the Pentagon, and Microsoft.
They hid inside a software update.
The SolarWinds attack is the most sophisticated supply chain attack ever documented. And the scariest part isn't how it happened. It's how long it was already inside before anyone noticed.
Let's reconstruct it — step by step.
First — What Is SolarWinds?
SolarWinds makes IT monitoring software called Orion. It's the kind of tool that sits at the center of an organization's network — watching servers, tracking performance, flagging issues.
If you control Orion, you can see everything the network sees.
That's exactly what the attackers understood.
Step 1 — They Picked The Perfect Target
Forget the 18,000 victims for a moment. The real target was SolarWinds itself.
Here's the logic: instead of attacking 18,000 organizations individually — each with their own security teams, firewalls, and detection tools — why not attack the one company whose software all of them trust unconditionally?
This is the core insight of a supply chain attack. You don't break through the front door. You get invited in through the back — disguised as something the target already trusts.
SolarWinds had over 300,000 customers worldwide. Orion was used by 425 of the Fortune 500. It had privileged access to the most sensitive networks on the planet. And it was pushing software updates directly to all of them.
It was the perfect vehicle.
Step 2 — They Got Inside The Build Pipeline
Sometime in late 2019 — over a year before discovery — attackers believed to be Russia's SVR intelligence unit gained access to SolarWinds' internal development environment.
Not the product. The pipeline that builds the product.
This distinction matters enormously. A software build pipeline is where source code gets compiled into the actual software that gets shipped to customers. It's the kitchen, not the restaurant. And most organizations treat their kitchen like it's untouchable — nobody thinks to monitor it the way they monitor production systems.
The attackers used this assumption against SolarWinds completely.
They studied the build process quietly for months. They learned how the code was compiled, how updates were signed, and how they would need to inject their own code without triggering any automated checks.
Then they waited.
Step 3 — The Implant Was Surgical
In February 2020, the attackers injected a small piece of malicious code — later named SUNBURST — into the Orion source code.
What made SUNBURST remarkable wasn't just what it did. It was what it deliberately didn't do.
It lay dormant for exactly 12 to 14 days after installation — enough time to evade automated sandbox analysis tools that typically run for shorter periods. It checked whether the infected system belonged to a security research company and went silent if so. It mimicked legitimate Orion network traffic patterns so precisely that even deep packet inspection tools would see nothing unusual. It communicated with command-and-control servers using subdomain patterns that looked identical to normal Orion telemetry.
This wasn't malware written by someone in a hurry. Every evasion was deliberate. Every timing decision was calculated. The people who built SUNBURST understood defensive security tools better than most defenders do.
Step 4 — The Update Goes Out
In March 2020, SolarWinds pushed Orion update version 2019.4 through 2020.2.1 to its customers.
The update was digitally signed — meaning it passed every standard security verification check. It came from a trusted vendor. It was installed by IT teams doing exactly what they were supposed to do.
18,000 organizations installed malware thinking they were patching their monitoring software.
Once inside, SUNBURST quietly mapped the network, identified high-value targets, and selectively escalated — meaning it only activated fully on networks the attackers considered worth the risk of exposure. Most of the 18,000 infected organizations were never actively exploited. They were collateral coverage. The attackers were after specific targets.
The US Treasury. The Department of Homeland Security. FireEye — one of the world's leading cybersecurity firms.
Step 5 — Discovery Came From The Outside
SolarWinds didn't discover the breach. Their own security tools didn't find it.
FireEye discovered it in December 2020 — only because they noticed an unusual device registration on their own network and traced it backwards. Nine months after the malicious update went live.
Nine months of unrestricted access across the most sensitive networks in the world.
What This Actually Means For You
The SolarWinds attack didn't succeed because SolarWinds had bad security. It succeeded because of three assumptions that almost every organization still makes today.
First assumption: trusted software is safe software. The attackers understood that digital signatures and vendor trust are not the same thing as security. If you can compromise the source, the signature means nothing.
Second assumption: if nothing is alerting, nothing is wrong. SUNBURST was engineered specifically to exist inside the gap between "what security tools monitor" and "what actually happens on a network." That gap is larger than most organizations realize.
Third assumption: sophisticated attacks happen to other people. The organizations that got hit weren't careless. They were following best practices. The attack was simply designed to bypass best practices entirely.
The Takeaway
SolarWinds changed how the security industry thinks about trust.
The question used to be: is this software from a trusted vendor? The question now has to be: how do I verify what this software actually does — regardless of where it came from?
That shift — from assumed trust to verified behavior — is the mental model that separates security programs built for yesterday's threats from those built for tomorrow's.
The attackers who built SUNBURST understood your defenses better than most defenders do. The only way to close that gap is to start thinking the same way they do.
That's exactly what we do here every week.
Think clearly.
— DJ Brar SKBSEC | SKB Decoded www.skbsec.com