(Much more informative than the related NYT article that came out last night.  
--rick)

SolarWinds hackers are back with a new mass campaign, Microsoft says
Dan Goodin - 5/28/2021, 4:15 AM

The Kremlin-backed hackers who targeted SolarWinds customers in a supply chain 
attack have been caught conducting a malicious email campaign that delivered 
malware-laced links to 150 government agencies, research institutions and other 
organizations in the US and 23 other countries, Microsoft said.

The hackers, belonging to Russia’s Foreign Intelligence Service, first managed 
to compromise an account belonging to USAID, a US government agency that 
administers civilian foreign aid and development assistance. With control of 
the agency’s account for online marketing company Constant Contact, the hackers 
had the ability to send emails that appeared to use addresses known to belong 
to the US agency.

Nobelium goes native

“From there, the actor was able to distribute phishing emails that looked 
authentic but included a link that, when clicked, inserted a malicious file 
used to distribute a backdoor we call NativeZone,” Microsoft Vice President of 
Customer Security and Trust Tom Burt wrote in a post published on Thursday 
evening. “This backdoor could enable a wide range of activities from stealing 
data to infecting other computers on a network.”

The campaign was carried out by a group that Microsoft calls Nobelium and is 
also known as APT29, Cozy Bear, and the Dukes. Security firm Kaspersky has said 
that malware belonging to the group dates back to 2008, while Symantec has said 
the hackers have been targeting governments and diplomatic organizations since 
at least 2010. There's more about the off-kilter and old-school coding 
characteristics of this group here.

Last December, Nobelium’s notoriety reached a new high with the discovery the 
group was behind the devastating breach of SolarWinds, an Austin, Texas maker 
of network management tools. After thoroughly compromising SolarWinds’ software 
development and distribution system, the hackers distributed malicious updates 
to about 18,000 customers who used the tool, which was called Orion. The 
hackers then used the updates to compromise nine federal agencies and about 100 
private-sector companies, White House officials have said.

< - >

https://arstechnica.com/gadgets/2021/05/microsoft-says-solarwinds-hackers-targeted-us-agencies-in-a-new-campaign/
-- 
Iw mailing list
[email protected]
http://sticklist.org/mailman/listinfo/iw_sticklist.org

Reply via email to