Magazine

SolarWinds Hack Continues to Spread: What You Need to Know

Posted on the 24 December 2020 by Thiruvenkatam Chinnagounder @tipsclear

A Russian intelligence agency is running an advanced malware campaign targeting US local, state and federal agencies, as well as private companies like Microsoft, such as the US State Department and Cybersecurity and Infrastructure Security Agency (CISA), news reports and security analysis firms. The massive breach that reportedly included an email system from executives in the finance department, began earlier this year when hackers compromised software at IT software company SolarWinds.

The hacked company sells software that enables a company to see what is happening on their computer networks. Hackers have put malicious code in an updated version of the software called Orion. Around 18,000 SolarWinds customers have installed the faulty updates on their systems. The compromised update process has had a widespread effect, the scope of which continues to grow as new information emerges.

Top tips from the editors

Subscribe to CNET Now for the day's most engaging reviews, news, and videos.

Over the weekend, President Donald Trump floated on Twitter with the idea that China could be behind the attack. Trump, who did not provide evidence to support the proposal for Chinese involvement, tagged Secretary of State Mike Pompeo, who had previously said in a radio interview, "We can say pretty clearly that it was the Russians who were involved in this activity."

In a joint statement, US national security agencies have described the breach as "significant and ongoing". It is still unclear how many agencies are affected or what information hackers may have stolen so far, but in any case the malware is extremely powerful. According to an analysis by Microsoft and the security company FireEye, both were infectedThe malware offers hackers a broad reach for affected systems.

Microsoft said it got identified more than 40 customers those were targeted in the hack. More information about the hack and its aftermath is likely to be released. Here's what you need to know about the SolarWinds hack:

How did hackers introduce malware into a software update?

Hackers gained access to a system that SolarWinds uses to compile updates for its Orion product, the company said in a filing with the SEC. From there, they injected malicious code into otherwise legitimate software updates. This is known as a supply chain attack because software is infected during assembly.

It is a big coup for hackers to launch a supply chain attack because it wraps their malware in trusted software. Rather than tricking individual targets into downloading malicious software with a phishing campaign, the hackers could rely on multiple government agencies and companies to install the Orion update at the request of SolarWinds.

The approach is particularly powerful in this case, as reports have shown that thousands of companies and government agencies around the world are using Orion software. With the release of the faulty software update, SolarWinds' extensive customer list became potential hacking targets.

Which government agencies were infected with the malware?

According to reports from Reuters, the Washington Post and the Wall Street Journal, the malware targeted the US Department of Homeland Security, State, Commerce and Treasury, and the National Institutes of Health. Politico reported on December 17 that nuclear programs by the US Department of Energy and the National Nuclear Security Administration were also being targeted.

According to Reuters, the federal agency for cybersecurity and infrastructure security (CISA) posted on its website on Dec. 23 that it is "tracking a major cyber incident affecting federal, state and local government business networks and critical infrastructure companies." other private sector organizations. "

It is still unclear what information, if any, has been stolen from federal agencies, but the scope of the access appears to be wide.

Although the Department of Energy and Commerce have recognized the news source hacks, there is no official confirmation that any other specific federal agencies were hacked. However, the US Cybersecurity and Infrastructure Security Agency issued a notice calling on federal agencies to mitigate the malware, stating that it is "currently being exploited by malicious actors."

In a December 17 statement, President-elect Joe Biden said his administration would "make addressing this violation a top priority from the time we take office."

Why is the hack a big deal?

Not only did the hackers gain access to multiple systems of government, they also turned an ordinary software update into a weapon. This weapon was aimed at thousands of groups, not just the agencies and companies the hackers focused on after installing the corrupted Orion update.

Microsoft President Brad Smith called this "an act of recklessness" in a long blog post examining the effects of the hack. He did not directly attribute the hack to Russia, but rather described his previous alleged hacking campaigns as evidence of an increasingly tense cyber conflict.

"This is not just an attack on specific targets," said Smith, "but on the trust and reliability of the world's critical infrastructure to advance a nation's intelligence." He continued to call for international agreements to limit the creation of hacking tools that undermine global cybersecurity.

Former Facebook cybersecurity chief Alex Stamos said on Twitter that the hack could lead to attacks in the supply chain more frequently. He did, however asked if the hack was something extraordinary for a well-equipped secret service.

"So far, all activities that have been publicly discussed have fallen within the limits of what the US does regularly," said Stamos.

Has the malware affected private companies or other governments?

Yes. Microsoft confirmed on December 17 that it had found indicators of the malware in its systems after confirming a few days earlier that the breach affects its customers. A Reuters report also states that Microsoft's own systems were used to promote the hacking campaign, but Microsoft denied this claim to news outlets. On December 16, the company began quarantining versions of Orion known to contain malware to keep hackers out of its customers' systems.

FireEye also confirmed that it was infected with the malware and that the infection was also appearing on customer systems.

On December 21, the Wall Street Journal announced it had uncovered at least 24 companies that had installed the malicious software. According to the Journal, these include the technology companies Cisco, Intel, Nvidia, VMware and Belkin. The hackers also reportedly had access to the California Department of State Hospitals and Kent State University.

It is unclear which other private SolarWinds customers have encountered malware infections. The company's customer list includes large companies such as AT&T, Procter & Gamble, and McDonald's. The company also counts among its customers for governments and private companies around the world. Many of these customers were infected, according to FireEye.

What do we know about Russia's involvement in the hack?

On December 18, Pompeo attributed the hack to Russia. It came after news outlets reported earlier this week that government officials said a hacking group known as Russian intelligence was responsible for the malware campaign. SolarWinds and cybersecurity companies attributed the hack to "nation-state actors" but did not directly name a country.

In a statement posted on Facebook, the Russian embassy in the US declined responsibility for the SolarWinds hacking campaign. "Malicious activity in the information space contradicts the principles of Russian foreign policy, national interests and our understanding of international relations," the embassy said, adding, "Russia does not conduct offensive cyber operations."

The hacking group, nicknamed APT29 or CozyBear, referred to in news reports, was previously accused of targeting email systems at the State Department and the White House during President Barack Obama's tenure. It was also named by US intelligence agencies as one of the groups that infiltrated email systems In the National Democratic Committee in 2015, but the leakage of these emails is not attributed to CozyBear. (Another Russian agency was blamed for this.)

More recently, the US, UK and Canada have identified the group as responsible for hacking efforts that attempted to access it Information on COVID-19 vaccine research.

Correction, December 23: This story has been updated to reflect that SolarWinds manufactures IT management software. In an earlier version of the story, the purpose of the products was incorrectly stated.


Back to Featured Articles on Logo Paperblog