FireEye uncovers a widespread global intrusion campaign that uses trojanized SolarWinds Orion updates to distribute the SUNBURST backdoor. The highly evasive threat actors, now attributed to APT29, use advanced techniques to blend in with legitimate network traffic.