Malwarebytes says it was hacked by group that breached SolarWinds, via Azure and Office 365 exploits, but attackers only accessed a subset of internal emails
ZDNetCatalin Cimpanu
Context & Ripple Effects
The reported intrusion extends a campaign already tied to Microsoft, where attackers accessed some source code through an employee account but not email. Microsoft's earlier disclosure of source-code viewing and Malwarebytes' narrower email exposure show the same group pursuing different assets through cloud-account access.
Malwarebytes must investigate the subset of internal emails accessed and assess whether their contents expose employees, customers, or ongoing security work.
Azure and Office 365 are implicated as the access route Malwarebytes identified, putting the security of those enterprise accounts at the center of containment and forensic review.
Second-order effects
Microsoft's prior source-code incident and Malwarebytes' email incident give organizations using Azure and Office 365 a concrete reason to review account protections and email-access monitoring, not only software-supply-chain exposure.
Security vendors and their customers face greater scrutiny of the sensitive material held in internal mail, since compromise of a cloud identity can yield intelligence without modifying software or systems.
Third-order effects
If similar incidents continue, breach preparedness will shift further from protecting a single software supplier toward limiting and detecting cloud-account access across vendors, customers, and internal communications.
The pattern also raises the strategic value of separating access to source code, support systems, and email, because the reported incidents show attackers targeting different information stores through account compromise.
The trend: SolarWinds-related incident response is broadening from compromised software to cloud identity and communications security across the affected organizations.
More information from our SolarWinds investigation. New tool - Raindrop - appears to have been used by attackers for spreading across victim networks. https://symantec-enterprise- blogs.security.com/... #SolarWinds #Raindrop #Sunburst https://twitter.com/...
Intrusion did not take place via a trojanized Orion app, since Malwarebytes doesn't use the software -Point of entry was described as “exploited an Azure Active Directory weakness” -Malwarebytes said it learned of the hack from Microsoft last month https://www.zdnet.com/...
“While Teardrop was used on computers that had been infected by the original Sunburst Trojan, Raindrop appeared elsewhere on the network, being used by the attackers to move laterally & deploy payloads on other computers” 🎶Raindrops keep fallin on my head(of incident response)🎶 h…
Symantec has discovered another tool used by the suspected Russian hackers behind the SolarWinds campaign. The new tool, “Raindrop,” seems to have been used to spread across networks after initial access. https://symantec-enterprise- blogs.security.com/... https://twitter.com/...
Moar SolarWinds related malware. Really interesting to see how this is all unfolding in the weeks since the attack was first revealed. https://twitter.com/...
“The investigation indicates the attackers leveraged a dormant email protection product within our Office 365 tenant that allowed access to a limited subset of internal company emails.” Okay, so tell us the “email protection product” that was compromised. https://blog.malwarebyte…
Ah! I had an early feeling of malicious O365 apps used by this threat actor, before we got to know about Solarwinds Orion. Turns out that O365 apps were also used, for targets without Orion: https://www.zdnet.com/... https://twitter.com/...
The “SolarWinds actor” has been busy. And we've likely only seen a small fraction of its activities. Interesting similarities in using/exploiting MSFT cloud services for reconnaissance activities. Mimecast: https://www.reuters.com/... Malwarebytes:https://blog.malwarebytes. com/ …
Remember the SolarWinds breach? Here's @mkleczynski confirming “the existence of another intrusion vector that works by abusing applications with privileged access to Microsoft Office 365 and Azure environments.” https://blog.malwarebytes.com/ ...
Malwarebytes feared it could become the next SolarWinds and spent the last month auditing its software source code -Said there's no sign UNC2452 poisoned any of its apps -Appears intruders only managed to access a few emails https://www.zdnet.com/...
Symantec discovered another malicious component used by SolarWinds hackers. The tool, which they're calling Raindrop, is part of second-stage activity, used only on high-value targets to load CobaltStrike and spread across the victim's network. https://symantec-enterprise- blogs.…
If you use Microsoft cloud tools, FireEye has some advice for stopping hackers from compromising your org's authentication services, something that the SolarWinds hackers have been doing after they initially breach a network. https://www.fireeye.com/...