The object is the SolarWinds Orion update channel in 2020. Customers fetched a Windows Installer patch from SolarWinds's own download site. The patch was signed by SolarWinds. It installed SolarWinds.Orion.Core.BusinessLayer.dll, a plugin the legitimate Orion host then loaded. That DLL contained the backdoor FireEye named SUNBURST. Applying the vendor-signed update was the recommended move. The signature was not a check that the bits matched the source the developers had reviewed.
Domain: software a vendor signs and ships as an update, especially a network-management platform that holds credentials to the hosts it watches. The comparison class is any product whose "apply the signed patch" step is treated as a security action.
If that reading is right, a vendor signature would not count as evidence that the binary matches reviewed source. Installing the next signed hotfix would not count as incident response until someone other than the vendor had examined the bits. Powering the product down, rather than patching it, would be the first move for this class of software. A network-management box would not sit on the domain as a patch-trusted host.
Ostensive specimen: Cybersecurity and Infrastructure Security Agency, Emergency Directive 21-01, 13 December 2020, "Mitigate SolarWinds Orion Code Compromise." Affected versions: 2019.4 through 2020.2.1 HF1. Required Action 2: immediately disconnect or power down those products. Agencies are to wait for CISA before using forthcoming patches to reinstall. Required Action 3: report SolarWinds.Orion.Core.BusinessLayer.dll with file hash b91ce2fa41029f6955bff20079468448. Background: "Disconnecting affected devices … is the only known mitigation measure currently available." The page now records the directive as closed (8 January 2026). https://www.cisa.gov/news-events/directives/ed-21-01-mitigate-solarwinds-orion-code-compromise-closed Same-night press release: https://www.cisa.gov/news-events/news/cisa-issues-emergency-directive-mitigate-compromise-solarwinds-orion-network-management-products
What the public record already names, not recap. FireEye, 13 December 2020: the DLL is a SolarWinds digitally-signed component of Orion; the trojanized version is SUNBURST; signed 24 March 2020 on the certificate with serial 0f:e9:73:75:20:22:a6:06:ad:f2:a3:6e:34:5d:c0:ed; posted to the SolarWinds updates website, including SolarWinds-Core-v2019.4.5220-Hotfix5.msp. After a dormant period of up to two weeks it talks out over HTTP, dressed as the Orion Improvement Program. https://cloud.google.com/blog/topics/threat-intelligence/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor/
SolarWinds Corporation, Form 8-K, 14 December 2020. The vulnerability was inserted in updates released between March and June 2020, "as a result of a compromise of the Orion software build system and was not present in the source code repository of the Orion products." About 33,000 Orion maintenance customers were notified. "Fewer than 18,000" may have had an installation that contained the vulnerability. Orion was about 45 percent of revenue for the nine months ended 30 September 2020. https://www.sec.gov/Archives/edgar/data/1739942/000162828020017451/swi-20201214.htm
CrowdStrike, 11 January 2021: SUNSPOT sat on the Orion build servers, watched for MsBuild.exe, replaced InventoryManager.cs while the product was being built, then put the original file back. The source repository stayed clean. The signed binary did not. https://www.crowdstrike.com/en-us/blog/sunspot-malware-technical-analysis/
Microsoft, 18 December 2020, analysis of the same DLL (Solorigate). Defender detects it as Trojan:MSIL/Solorigate. https://www.microsoft.com/en-us/security/blog/2020/12/18/analyzing-solorigate-the-compromised-dll-file-that-started-a-sophisticated-cyberattack-and-how-microsoft-defender-helps-protect/
Follow-on, not the 18,000. Brad Smith, Microsoft, written testimony, Senate Select Committee on Intelligence, 23 February 2021: Anne Neuberger's 17 February estimate was about 100 private-sector companies and nine U.S. government agencies. Kevin Mandia, FireEye, same hearing: FireEye found the implant by reversing the signed Orion platform, then told SolarWinds on 12 December and published indicators on 13 December. https://www.intelligence.senate.gov/wp-content/uploads/2024/08/sites-default-files-documents-os-bsmith-022321.pdf https://www.intelligence.senate.gov/wp-content/uploads/2024/08/sites-default-files-documents-os-kmandia-022321.pdf
Attribution, 15 April 2021. The U.S. government attributes the activity to the Russian Foreign Intelligence Service (SVR). CISA recorded that on the directive page. White House fact sheet: https://www.whitehouse.gov/briefing-room/statements-releases/2021/04/15/fact-sheet-imposing-costs-for-harmful-foreign-activities-by-the-russian-government/ CISA alert AA20-352A: https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a
This post is the public case, not a recap of an essay.