The hits keep on coming from the SolarWinds breach. More security vendors including Qualys, Mimecast, and Fidelis Cybersecurity confirmed that suspected Russian hackers targeted their networks following a report by security firm Netresec that identified 23 additional SolarWinds’ victims “singled out as interesting targets by the threat actors.”
Qualys confirmed that the SolarWinds attackers targeted its systems. However, “there was no impact on our production environment nor any exfiltrated data,” a spokesperson said in an email to SDxCentral.
Fidelis CISO Chris Kubic said that the threat detection and response firm continues to investigate the attack. “To date we have not turned up any evidence that the SolarWinds compromise has impacted our networks, although our analysis continues,” he wrote in a blog post.
Email security vendor Mimecast appears to be the most impacted from the SolarWinds breach. Two weeks ago, it disclosed that a “sophisticated threat actor” broke into its network and used its digital certificates to access some of its customers’ Microsoft 365 accounts. On Tuesday, following the Netresec report, Mimecrast confirmed that the SolarWinds hackers were responsible for its network breach.
And while Palo Alto Networks was also named in the Netresec report, the security vendor confirmed last month that the SolarWinds attack was linked to earlier security incidents against its network that it successfully prevented.
23 New Targeted DomainsIn the new report, threat researcher Erik Hjelmvik said he used a decoder tool to determine domains that hackers targeted with Sunburst malware — this is the name researchers gave to the malicious code that hackers inserted into a SolarWinds’ Orion update beginning last spring.
While SolarWinds pushed the software update to about 18,000 Orion customers, “we’d like to stress that the majority of all companies and organizations that have installed a backdoored SolarWinds Orion update were never targeted by the threat actors,” Hjelmvik wrote. This means the Sunburst attacks never progressed beyond what he calls “stage one operations,” and this is important because the hackers cannot use the malware to steal information from organizations unless the attack progressed to the second stage. Netresec’s research focuses on domains targeted during stage two of the attacks.
This doesn’t, however, necessarily mean that the hackers were successful. The research doesn’t specify if attackers exfiltrated data from any of the new victims on the list. Additionally, in some cases the organizations themselves — such as Cisco — have already confirmed that yes, they did use the Orion platform, but they have since removed the installations, blocked access to the control and command servers, and aren’t aware of any impact to their products or customers’ data.
In addition to the security firms, Netresec’s new report includes government agencies including the National Guard that the hackers targeted in the second stage of the attacks. The list also includes a West Virginia windows and doors company, WincoreWindows.local. This one, Hjelmvik wrote, is “interesting” because it, along with another targeted domain (wctc.msft) provides further indication that the hackers specifically went after Microsoft’s network.
SolarWinds Hackers Targeted Government, Big TechWhile neither of those two domains proved successful, the attackers did at some point find a backdoor into Microsoft’s systems. On Dec. 31, the software giant disclosed that hackers used the Sunburst trojan (Microsoft, which prefers to assign its own names to malware and hacking groups, calls it “Solorigate”) to access its internal source code.
In addition to Microsoft and Cisco, major corporations including VMware, Intel, Nvidia, Cox Communications, FireEye, and CrowdStrike previously disclosed that the SolarWinds hackers targeted their systems.
Earlier reports indicate that the suspected Russian hackers, which managed the attack from servers inside the U.S., gained access to as many as 250 networks. This includes the U.S. Commerce and Treasury Departments, Department of Homeland Security, the Federal Energy Regulatory Commission, the Los Alamos National Laboratory, the Sandia National Laboratories, the Office of Secure Transportation at NNSA, and the Richland Field Office of the DOE.
“Early warning” sensors that Cyber Command and the National Security Agency put inside foreign networks to detect attacks in progress failed, and there is no indication that human intelligence alerted the government to the hack, according to The New York Times.
Comments