As many as 18,000 SolarWinds customers installed the company’s Orion software updates containing malicious code likely inserted by Russian nation-state hackers, according to documents filed with the U.S. Securities and Exchange Commission on Monday.

The SolarWinds attack may have also hit Microsoft customers. In its SEC filing, SolarWinds said the hackers compromised its Office 365 email and office productivity accounts.

“SolarWinds, in collaboration with Microsoft, has taken remediation steps to address the compromise and is investigating whether further remediation steps are required, over what period of time this compromise existed, and whether this compromise is associated with the attack on its Orion software build system,” the document said. “SolarWinds also is investigating in collaboration with Microsoft as to whether any customer, personnel or other data was exfiltrated as a result of this compromise but has uncovered no evidence at this time of any such exfiltration."

ExtraHop IDs IP Addresses

And today, ExtraHop said it uncovered new information that will help enterprises determine if they’ve been compromised as a result of the SolarWinds hack. The ExtraHop data science team used a combination of open source and proprietary tools, and they identified a list of about 550 unique IP addresses that the attackers used in the campaign and should be considered suspicious.

“While many of these IPs are no longer active, we recommend that organizations search for activity to these IPs over a long-time interval. The SUNBURST trojan is dormant for long periods of time and might only occasionally perform DNS resolutions,” ExtraHop CTO and co-founder Jesse Rothstein said. “We believe that the full extent of this attack is yet to be determined and are sharing these [indicators of compromise] with the broader security community with the hope that it can help some of the impacted organizations who do not yet realize that they’ve been compromised.”

SolarWinds disclosed the breach late Sunday in a security advisory about the supply chain attack on its Orion platform update issued between March and June. “We have been advised this attack was likely conducted by an outside nation state and intended to be a narrow, extremely targeted, and manually executed attack, as opposed to a broad, system-wide attack,” the advisory said.

Security vendor FireEye was one of the organizations hit by the attack, which it disclosed last week, along with multiple U.S. government agencies including the Treasury and Commerce departments, the State Department, the Department of Homeland Security, and “parts” of the Pentagon, according to the New York Times.

When it initially disclosed the attack, FireEye said it was coordinating its investigation with the FBI and Microsoft.

CISA, NSA Hit Emergency Button

Shortly after SolarWinds published its advisory, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive — only its fifth in five years — urging federal civilian agencies to review their networks for indicators of compromise and disconnect or power down SolarWinds Orion products immediately.

“The compromise of SolarWinds’ Orion Network Management Products poses unacceptable risks to the security of federal networks,” CISA Acting Director Brandon Wales said in a statement. “Tonight’s directive is intended to mitigate potential compromises within federal civilian networks, and we urge all our partners — in the public and private sectors — to assess their exposure to this compromise and to secure their networks against any exploitation.”

Additionally, the National Security Council activated an emergency cybersecurity process to help the government plan its response and recovery efforts, according to a CyberScoop report citing White House officials and other sources.

SolarWinds has some 300,000 customers, but according to SEC documents filed this week, and first reported by ZDNet, only 33,000 use Orion, and about 18,000 are believed to have installed the trojanized update. The vendor said it notified all of its Orion customers about the breach and mitigation steps.

Neither SolarWinds nor FireEye have confirmed that Russian hackers were behind the attack, but multiple news outlets blamed a Russian state-sponsored group nicknamed APT29 or Cozy Bear.

SolarWinds Attack Scope Unclear

While the fallout from the attack continues, and new government agencies disclosing almost on a daily basis that their networks were compromised, it’s unlikely that the general public will know the full scope of the hack, said Kelvin Coleman, executive director of the National Cyber Security Alliance. The NCSA is a Washington, D.C.-based public-private coalition that advocates for cybersecurity awareness. Coleman previously spent 20 years in cybersecurity posts at the White House, DHS, and private sector where he worked at FireEye.

“Typically, on a wide-scale attack like this, you’ll see more government agencies come out and say, ‘yeah, we were attacked.’ But on the private-sector side, not everyone is necessarily required to come out and say it, so we may not ever know the full number of people who were attacked,” he said. “But I fully expect others to come forward the next couple of days.”

Microsoft Seizes Domain Name

Meanwhile, Microsoft this week took over domain name, avsvmcloud[.]com, used in the attack to communicate with compromised systems, according to KrebsonSecurity and other news organizations. This move, which Microsoft has used in the past to seize control of domains used in other global malware attacks, should allow the software giant to better determine how many other organizations were hit.

And as of this morning, Microsoft’s Defender Antivirus product began blocking the known malicious SolarWinds binaries.

“There is a high probability that we will continue to see high-profile attacks targeting the U.S. government, cybersecurity providers, and their customers in the foreseeable future,” Cybereason CEO Lior Div wrote in an email to SDxCentral. Div is a former commander in the Israeli Unit 8200 where he was in charge of carrying out large-scale cyber offensive campaigns.

“Any high-value targets should be on alert and initiate threat hunting and compromise assessments to assure they are not being targeted in nation-state operations,” he continued, adding that it’s not a coincidence that the SolarWinds attack happened during a contentious U.S. presidential election while the government’s bare-bones cybersecurity staff worked to combat disinformation campaigns related to the election and COVID-19 research and vaccine dissemination. “Adversaries like Russia look for this kind of instability and distraction to exploit for their benefit,” he said.

Make Cybersecurity Hygiene Great Again

“SolarWinds has a stellar reputation, and from the available information it looks like their software was signed with a valid Symantec certificate on a normal SolarWinds Orion update — no hygiene in the world would prevent that,” Div added. “The only solution is a robust, behavioral, post-breach mindset. After a certain point, effective detection matters more.”

There’s not really a new lesson learned from this breach, Coleman said. Instead, it’s the same-old message that basic cybersecurity hygiene is vital. “It’s reiterating and stressing the old message of being super diligent,” he said.

While the SolarWinds attack was admittedly a highly sophisticated, targeted attack, “generally speaking, the majority of attacks will come from just spraying the net across the river and catching what you can,” Coleman said. “And there’s actually a great deal we can do about that. Passwords still are very important, patching your machine, multi-factor authentication.”