By Alan Suderman

Microsoft said Monday the same Russia-backed hackers responsible for the 2020 SolarWinds breach continue to attack the global technology supply chain and have been relentlessly targeting cloud service companies and others since summer.

The group, which Microsoft calls Nobelium, has employed a new strategy to piggyback on the direct access that cloud service resellers have to their customers' IT systems, hoping to “more easily impersonate an organization’s trusted technology partner to gain access to their downstream customers." Resellers act as intermediaries between giant cloud companies and their ultimate customers, managing and customizing accounts.

“Fortunately, we have discovered this campaign during its early stages, and we are sharing these developments to help cloud service resellers, technology providers, and their customers take timely steps to help ensure Nobelium is not more successful,” Tom Burt, a Microsoft vice president, said in a blog post.

The Biden administration downplayed Microsoft’s announcement. A U.S. government official briefed on the issue who insisted on anonymity to discuss the government’s response noted that “the activities described were unsophisticated password spray and phishing, run-of-the mill operations for the purpose of surveillance that we already know are attempted every day by Russia and other foreign governments.”

The Russian Embassy did not immediately reply to a request for comment.

U.S. and Russian ties have already been strained this year over a string of high-profile ransomware attacks against U.S. targets launched by Russia-based cyber gangs. U.S. President Joe Biden has warned to Russian President Vladimir Putin to get him to crack down on ransomware criminals, but several top administration cybersecurity officials have said recently that they have seen no evidence of that.

Supply chain attacks allow hackers to steal information from multiple targets by breaking into a single product they all use. The U.S. government has previously blamed Russia’s SVR foreign intelligence agency for the SolarWinds hack, a supply-chain hack which went undetected for most of 2020, compromised several federal agencies and badly embarrassing Washington.

Microsoft has been observing Nobelium’s latest campaign since May and has notified more than 140 companies targeted by the group, with as many as 14 believed to have been compromised. The attacks have been increasingly relentless since July, with Microsoft noting that it had informed 609 customers that they had been attacked 22,868 times by Nobelium, with a success rate in the low single digits. That’s more attacks than Microsoft had flagged rom all nation-state actors in the previous three years.

“Russia is trying to gain long-term, systematic access to a variety of points in the technology supply chain and establish a mechanism for surveilling – now or in the future – targets of interest to the Russian government,” Burt said.

Microsoft did not name any of the hackers’ targets in their latest campaign. But cybersecurity firm Mandiant said it had seen victims in both Europe and North America.

Mandiant Chief Technology Officer Charles Carmakal said the hackers' method of going after resellers make detection difficult.

“It shifts the initial intrusion away from the ultimate targets, which in some situations are organizations with more mature cyber defenses, to smaller technology partners with less mature cyber defenses," he said.

___

AP Business Writer Matt Ott in Silver Spring, Maryland, contributed to this report.

Share:
More In Business
State Department Halts Plan to buy $400M of Armored Tesla Vehicles
The State Department had been in talks with Elon Musk’s Tesla company to buy armored electric vehicles, but the plans have been put on hold by the Trump administration after reports emerged about a potential $400 million purchase. A State Department spokesperson said the electric car company owned by Musk was the only one that expressed interest back in May 2024. The deal with Tesla was only in its planning phases but it was forecast to be the largest contract of the year. It shows how some of his wealth has come and was still expected to come from taxpayers.
Goodyear Blimp at 100: ‘Floating Piece of Americana’ Still Thriving
At 100 years old, the Goodyear Blimp is an ageless star in the sky. The 246-foot-long airship will be in the background of the Daytona 500 — flying roughly 1,500 feet above Daytona International Speedway, actually — to celebrate its greatest anniversary tour. Even though remote camera technologies are improving regularly and changing the landscape of aerial footage, the blimp continues to carve out a niche. At Daytona, with the usual 40-car field racing around a 2½-mile superspeedway, views from the blimp aptly provide the scope of the event.
Is U.S. Restaurants’ Breakfast Boom Contributing to High Egg Prices?
It’s a chicken-and-egg problem: Restaurants are struggling with record-high U.S. egg prices, but their omelets, scrambles and huevos rancheros may be part of the problem. Breakfast is booming at U.S. eateries. First Watch, a restaurant chain that serves breakfast, brunch and lunch, nearly quadrupled its locations over the past decade to 570. Fast-food chains like Starbucks and Wendy's added more egg-filled breakfast items. In normal times, egg producers could meet the demand. But a bird flu outbreak that has forced them to slaughter their flocks is making supplies scarcer and pushing up prices. Some restaurants like Waffle House have added a surcharge to offset their costs.
Trump Administration Shutters Consumer Protection Agency
The Trump administration has ordered the Consumer Financial Protection Bureau to stop nearly all its work, effectively shutting down the agency that was created to protect consumers after the 2008 financial crisis and subprime mortgage-lending scandal. Russell Vought is the newly installed director of the Office of Management and Budget. Vought directed the CFPB in a Saturday night email to stop work on proposed rules, to suspend the effective dates on any rules that were finalized but not yet effective, and to stop investigative work and not begin any new investigations. The agency has been a target of conservatives since President Barack Obama created it following the 2007-2008 financial crisis.
Load More