Martin's Blog

2. The Threat Actor

A note on what this chapter can and cannot prove. No binary names its author. Nothing in the four installers or the companion samples examined for this book establishes a nationality, a sponsor, or a building in Moscow. Nation-state attribution is a separate discipline that rests on the broader investigation, infrastructure correlation, victim pattern of life, and intelligence sources that vendors do not publish, and ultimately on a government’s decision to say so on the record. This chapter therefore draws on the public record (cited), and is honest about the seam between what the code shows (§2.4 and the artifact comparisons in §2.3) and who the public record says built it. The strongest analytic statement is not that any one fact proves identity; it is that the case is cumulative, and that the convergence is now very strong.

2.1 One actor, many names

If you read the SolarWinds reporting from late 2020 through 2022, you meet what looks like a crowd. It is one group. The proliferation of names is an artifact of how the security industry tracks adversaries: vendors name activity clusters from their own visibility, often before anyone is willing to name a sponsor, and it is worth untangling once, because the literature uses these labels interchangeably.

Name Coined by What it denotes Note
UNC2452 Mandiant / FireEye An uncategorized cluster, correlated activity not yet attributed to a known group. Mandiant merged UNC2452 into APT29 in April 2022; the UNC####APT## graduation is the whole point of the label.
StellarParticle CrowdStrike CrowdStrike’s activity cluster name for the same intrusion set. Initially attribution-neutral; CrowdStrike later associated StellarParticle with Cozy Bear / APT29 / The Dukes.
NOBELIUM Microsoft Microsoft’s actor name, adopted March 2021. Renamed Midnight Blizzard under Microsoft’s 2023 weather taxonomy, same actor; noted so you can cross-reference modern reporting.
Dark Halo Volexity Volexity’s cluster from think tank incidents it worked in 2019–2020. Tied to SolarWinds-related activity via overlapping C2 and other indicators.
Solorigate Microsoft The malware / incident name, not the actor. Often used loosely as a campaign label; keep it distinct from the actor.
SUNBURST FireEye / industry The backdoor / incident name. Likewise a malware name, not an actor.
APT29 / Cozy Bear / The Dukes / CozyDuke Mandiant / CrowdStrike / earlier research The long-standing names for the SVR-linked espionage group. Tracked publicly for years before SolarWinds.
SVR US / UK governments The sponsor: Russia’s foreign intelligence service (Sluzhba vneshney razvedki). The April-2021 formal attribution.
G0016 + aliases MITRE ATT&CK The catalog entry that ties the aliases together. Also lists IRON RITUAL, IRON HEMLOCK, NobleBaron, YTTRIUM, Blue Kitsune, and SolarStorm (Palo Alto Unit 42).

The mental model that keeps this straight:

When this book needs to be precise about the early, pre-attribution phase it uses UNC2452; when it means the group, APT29; when it means the sponsor, the SVR.

A crucial subtlety in the public reporting is that the early cluster names reflected deliberate epistemic caution, not branding. In December 2020, FireEye, Microsoft, and Volexity each declined to attribute to APT29; the consolidation came later (Mandiant’s formal merge in 2022). Treating “UNC2452” as a synonym for “APT29” is correct today but was not a claim any of those vendors was making on day one.

2.2 Who the actor is, and how firmly we know it

(Public record, cited, not inferred from the binaries.)

APT29 / Cozy Bear is one of the most-studied state-sponsored espionage actors, publicly tracked for years (research handles like The Dukes / CozyDuke predate the APT29 label; Mandiant has tracked the group since 2014). Its consistent characterization across vendor and government reporting is a strategic intelligence collector, long-dwell access to high-value government, diplomatic, policy, and technology targets, prizing operational security and patience over speed or noise.

This was espionage, not sabotage. Every authoritative source assesses the objective as intelligence collection: no destructive payloads, no ransomware, no wiper. The actor maintained access for roughly 14 months and used victim gating to stay dark. The SolarWinds operation fits the APT29 profile precisely: the point of distributing affected updates to an upper bound population of roughly 18,000 potentially affected customers was not to exploit all of them, but to use breadth as a funnel to a small espionage target set. Chapter 5 shows that the DNS answers acted as control signals, while also explaining why the passive DNS address set cannot establish a victim-level promotion ratio.

How firm is attribution? The public assessments are careful to grade their confidence, and so is this book:

That convergence, from independent governments and vendors, is why the assessment is treated as high-confidence in an analytic sense. But two honest caveats travel with it:

  1. SolarWinds itself never endorsed the actor attribution. Its CEO stated the company’s investigations “have not independently verified the identity of the perpetrators.” That is a vendor declining to make a call outside its evidence, not a counterclaim, but it belongs in any honest account.
  2. Attribution is cumulative, not artifactual. No single sample examined for this book, and no single indicator in the public set, “proves” the SVR. The case is the convergence of official attribution, consistent vendor clustering, the espionage objective, the patience and scale, and the resourcing required. Reporting that there was, by 2021, no serious surviving alternative (early speculation ranged from China to other Russian services and was substantially narrowed by the Jan-2021 and Apr-2021 statements) is itself part of the cumulative case.

Scale and resourcing. The engineering effort and parallel operations support the public assessment of a well-resourced state service. Mandiant’s later merge emphasizes the group’s scale, longevity, operational tempo, and unusually disciplined OPSEC. Public discussion sometimes turns that qualitative judgment into a precise staffing estimate; this book does not, because the public record does not provide an auditable project headcount.

Before and after SolarWinds (cited history, for context). APT29 did not begin or end with Orion. Public reporting documents a long arc:

The 2024 Microsoft intrusion is a pointed epilogue: the same actor, years later, walking in through a forgotten account with no MFA. The tradecraft is patient and identity-centric; the entry is often mundane.

These campaign history items come from the public reporting listed under Sources & evidence. They provide background; they are not findings derived from the malware analysis in this book.

2.3 The attribution boundary: who is not this actor

Attribution discipline cuts both ways, and SolarWinds has a notorious trap. Riding the same product, Orion, in the same window was a second piece of malware, SUPERNOVA (Chapter 7). It is a .NET webshell whose reported deployments were associated with Orion exploitation, including the authentication bypass vulnerability CVE-2020-10148. It shares no code with SUNBURST, involved no build pipeline compromise and no SolarWinds code signing, and Mandiant explicitly does not attribute it to UNC2452. It is a separate, unrelated intrusion that happened to target the same software. SolarWinds’ own FAQ treats SUNBURST and SUPERNOVA as distinct problems with distinct fixes.

Two further “do not over-merge” cautions follow from the cited public reporting:

The most common analytical error around this incident is to fold every Orion-adjacent indicator from late 2020 into one campaign and one actor. “Same product” is not “same actor”; “same region” is not “same service.” Chapter 7 keeps the SUPERNOVA boundary explicit for exactly this reason.

2.4 What the artifacts themselves say about the operator

This is what the artifacts can speak to. You cannot read a nationality out of the code, but you can read discipline, resourcing, and intent, and the picture is consistent with the public profile in §2.2, arrived at here from the binaries rather than from reputation. These observations are grounded in the decompiled artifacts and developed in later chapters:

None of this is attribution. But it is the signature of a well-resourced, patient, detection-averse espionage operator, precisely the public characterization of APT29 in §2.2, here read out of the code.

2.5 The road to attribution

Public attribution did not arrive in one statement; it tightened over roughly four months after disclosure, then was reinforced a year later when Mandiant folded the cluster into APT29. The milestones (dates from primary/public reporting; the early language is quoted to show how guarded it was):

Date Event Significance
5 Jan 2021 Cyber Unified Coordination Group (FBI, CISA, ODNI, NSA) calls the actor “likely Russian in origin,” intelligence-focused; “fewer than 10” federal agencies then identified. First US government attribution, deliberately hedged (“likely”).
11 Jan 2021 CrowdStrike publishes the SUNSPOT build injector analysis (cluster StellarParticle); SolarWinds’ aligned root cause findings. Confirmed how the code was inserted without alarming developers (Chapter 3).
4 Mar 2021 Microsoft details GoldMax / GoldFinder / SIBOT, attributing them to NOBELIUM. Mapped the actor’s later toolkit (Chapter 9) to the same group.
15 Apr 2021 US formally attributes to the SVR (“high confidence”); UK NCSC concurs (“highly likely”); Treasury sanctions, 10 diplomats expelled; NSA/CISA/FBI advisory frames SolarWinds within a wider SVR campaign. The hedge is dropped: a named sponsor, with consequences (Chapter 10).
2022 Mandiant merges UNC2452 into APT29. The provisional cluster graduates to the established group; the attribution “closes.”

The progression is itself the lesson. Early language was cautious because public attribution is a high bar; vendor reporting through January and March filled in the technical cluster (the injector, the second stage, the later tooling); the government committed to the SVR by name in April and acted on it; and the cluster-to-group merge in 2022 retired the last of the hedged labels. The response and consequences of that April-2021 moment, sanctions, the emergency directive, the landmark SEC case, and the supply-chain policy shift, are the subject of Chapter 10.

Sources & evidence

↑ Revisiting the SolarWinds Compromise