/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Sources: hackers conducted a test run of the SolarWinds breach in October 2019, with a version of the malware that didn't have a backdoor embedded in it

Kim Zetter / Yahoo News :

Yahoo News Kim Zetter

Context & Ripple Effects

Kim Zetter's reporting pushes the SolarWinds intrusion timeline back further than the public record suggested: a dry run in October 2019 using malware without the embedded backdoor, more than a year before disclosure. That reframes what investigators already knew — the DOJ reportedly found the breach in late May 2020 but missed its significance, and Microsoft later confirmed the same group viewed its source code through an employee account.

The test-run detail matters because it shows a staged operation rather than a single opportunistic strike: rehearse delivery, then arm it. Investigators are still tracing the entry path, including whether the Czechia, Poland, and Belarus engineering offices were the way in, and the dwell-time question now stretches across every victim that has disclosed exposure, from SolarWinds to Malwarebytes.

First-order effects

  • SolarWinds' known compromise window extends to at least October 2019, lengthening the period customers and investigators must audit for attacker activity and complicating the company's disclosure timeline.
  • Victims that have already disclosed — Microsoft with its source code, Malwarebytes with its internal emails — face renewed questions about how long the group was inside before detection, given the operation was rehearsing more than a year before disclosure.

Second-order effects

  • The DOJ's failure to flag its May 2020 discovery becomes harder to defend as a routine miss if the intrusion was active and testable from 2019, feeding scrutiny of how federal agencies triage breach indicators.
  • SolarWinds' corporate trajectory — the $4.4 billion Turn/River take-private and the largely dismissed SEC charges against Tim Brown — gets re-litigated in public perception as each new timeline detail lands.

Third-order effects

  • A rehearsed, multi-stage supply-chain intrusion with a year-plus dwell time hardens the case that software build-and-distribution pipelines, not endpoints, are the strategic target for nation-state operators.
  • If the pattern holds, breach disclosure norms shift from announcing an incident to reconstructing a full operational history first — a standard the DOJ's early discovery and the October test run suggest the industry has not met.

The trend: Nation-state supply-chain intrusions are being revealed as long, staged campaigns whose dwell times keep expanding backward, forcing software vendors and government agencies to treat build pipelines as primary attack surface.

Discussion

  • @kimzetter Kim Zetter on x
    New: SolarWinds hackers did test-run of spy operation in Oct 2019, when malicious SolarWinds files were first downloaded by customers. That version didn't have backdoor in it, however. Indicates hackers were in SolarWinds network in 2019, if not earlier. https://news.yahoo.com/..…
  • @dangoodin001 Dan Goodin on x
    Reason No. 5 gazillion why the SolarWinds hack is so impressive. The hackers had full control of SolarWinds' software build system since October 2019. We know this because the hackers performed a dry run exercise that month. Great reporting by @KimZetter https://news.yahoo.com/..…
  • @diakopter @diakopter on x
    @thespybrief “The DOJ, FBI and DOD..., have moved routine communication onto classified networks that are believed not to have been breached, according to two people briefed on the measures. They are assuming that the non-classified networks have been accessed” https://www.reuter…
  • @scottmstedman Scott Stedman on x
    “Like other SolarWinds customers, we have been actively looking for indicators of this actor and can confirm that we detected malicious Solar Winds binaries in our environment, which we isolated and removed,” a Microsoft spokesperson said https://www.reuters.com/...