Sources: hackers conducted a test run of the SolarWinds breach in October 2019, with a version of the malware that didn't have a backdoor embedded in it
Kim Zetter / Yahoo News :
Context & Ripple Effects
Kim Zetter's reporting pushes the SolarWinds intrusion timeline back further than the public record suggested: a dry run in October 2019 using malware without the embedded backdoor, more than a year before disclosure. That reframes what investigators already knew — the DOJ reportedly found the breach in late May 2020 but missed its significance, and Microsoft later confirmed the same group viewed its source code through an employee account.
The test-run detail matters because it shows a staged operation rather than a single opportunistic strike: rehearse delivery, then arm it. Investigators are still tracing the entry path, including whether the Czechia, Poland, and Belarus engineering offices were the way in, and the dwell-time question now stretches across every victim that has disclosed exposure, from SolarWinds to Malwarebytes.
First-order effects
- SolarWinds' known compromise window extends to at least October 2019, lengthening the period customers and investigators must audit for attacker activity and complicating the company's disclosure timeline.
- Victims that have already disclosed — Microsoft with its source code, Malwarebytes with its internal emails — face renewed questions about how long the group was inside before detection, given the operation was rehearsing more than a year before disclosure.
Second-order effects
- The DOJ's failure to flag its May 2020 discovery becomes harder to defend as a routine miss if the intrusion was active and testable from 2019, feeding scrutiny of how federal agencies triage breach indicators.
- SolarWinds' corporate trajectory — the $4.4 billion Turn/River take-private and the largely dismissed SEC charges against Tim Brown — gets re-litigated in public perception as each new timeline detail lands.
Third-order effects
- A rehearsed, multi-stage supply-chain intrusion with a year-plus dwell time hardens the case that software build-and-distribution pipelines, not endpoints, are the strategic target for nation-state operators.
- If the pattern holds, breach disclosure norms shift from announcing an incident to reconstructing a full operational history first — a standard the DOJ's early discovery and the October test run suggest the industry has not met.
The trend: Nation-state supply-chain intrusions are being revealed as long, staged campaigns whose dwell times keep expanding backward, forcing software vendors and government agencies to treat build pipelines as primary attack surface.