The Russian state-sponsored hackers behind the SolarWinds attack likely gained access to the software provider’s environment as early as January 2019, SolarWinds CEO Sudhakar Ramakrishna said during an RSA Conference keynote today.

SolarWinds executives had originally thought that the attack, which wasn’t discovered until December 2020, originated in the fall of 2019. “But as we've been looking back into our history … they were doing very early recon activities in January of 2019,” Ramakrishna said.

After the attackers broke into SolarWinds, they inserted malware into the vendor’s Orion software update that was pushed to about 18,000 customers beginning in March 2019. This allowed them to remain in organizations’ environments for months without being detected. Threat researchers now believe the Russian attackers compromised about 100 private corporations and nine federal agencies’ networks.

“The tradecraft that the attackers used was extremely well done, and extremely sophisticated, where they did everything possible to hide in plain sight,” Ramakrishna said at RSA. “We were looking for all the usual clues. When you go through an investigation, you have a checklist, you have a set of hypothesis, you try to map things. And in this particular case, given the amount of time they spent, and given the deliberateness that they had in their efforts, they were able to cover their fingerprints, cover their tracks, at every step of the way. Given the resources of a nation state … it was a very difficult thing to uncover.”

While Ramakrishna didn’t discuss the specifics of how the attackers gained access, at an earlier event he said SolarWinds’ internal investigation has narrowed down the initial entry point from 16 possibilities down to three. Those three “painfully become routine,” he added.

“We are investigating a very targeted spear phishing attack,” Ramakrishna said. “Two is a vulnerability at that point in time in one of the third-party softwares that we have, which went unpatched and that might have exposed an entry point into our systems. And the third one is a credential compromise of a few specific users.”