Malwarebytes says it was hacked by group that breached SolarWinds, via Azure and Office 365 exploits, but attackers only accessed a subset of internal emails
The SolarWinds incident was already extending beyond Orion-focused investigation: FireEye had released a tool to check for known attacker techniques, while Microsoft disclosed that an employee-account compromise exposed some source code without email access. Malwarebytes adds a security vendor whose exposure was centered on cloud productivity systems and internal mail.
Malwarebytes must investigate the subset of internal email accessed through the Azure and Office 365 compromise and assess what information those mailboxes exposed.
Microsoft’s Azure and Office 365 environments become part of the incident-response scope for a campaign already associated with intrusions at Microsoft, FireEye, CrowdStrike, and Malwarebytes.
Second-order effects
Security teams using Microsoft cloud identity and email services have a stronger reason to pair SolarWinds-focused checks with review of account access and mailbox exposure, rather than limiting inquiries to Orion systems.
FireEye’s network-audit tool gains practical relevance for organizations seeking evidence of the techniques associated with the reported group, while separate-malware reporting keeps detection and attribution work from collapsing into a single signature set.
Third-order effects
The pattern points to a supply-chain incident evolving into a broader identity-and-cloud-security problem: security vendors themselves are targets, and post-breach assessments increasingly span software, employee accounts, and hosted communications.
If distinct groups continue to exploit the same vendor ecosystem with different malware, defenders and investigators will need to separate campaigns by tactics and access paths rather than organize response solely around the SolarWinds name.
The trend: The SolarWinds episode is becoming a wider campaign narrative in which software supply-chain exposure, cloud account compromise, and attacks on security vendors must be investigated together but attributed separately.
Intrusion did not take place via a trojanized Orion app, since Malwarebytes doesn't use the software -Point of entry was described as “exploited an Azure Active Directory weakness” -Malwarebytes said it learned of the hack from Microsoft last month https://www.zdnet.com/...
More information from our SolarWinds investigation. New tool - Raindrop - appears to have been used by attackers for spreading across victim networks. https://symantec-enterprise- blogs.security.com/... #SolarWinds #Raindrop #Sunburst https://twitter.com/...
“The investigation indicates the attackers leveraged a dormant email protection product within our Office 365 tenant that allowed access to a limited subset of internal company emails.” Okay, so tell us the “email protection product” that was compromised. https://blog.malwarebyte…
“While Teardrop was used on computers that had been infected by the original Sunburst Trojan, Raindrop appeared elsewhere on the network, being used by the attackers to move laterally & deploy payloads on other computers” 🎶Raindrops keep fallin on my head(of incident response)🎶 h…
Ah! I had an early feeling of malicious O365 apps used by this threat actor, before we got to know about Solarwinds Orion. Turns out that O365 apps were also used, for targets without Orion: https://www.zdnet.com/... https://twitter.com/...
Symantec has discovered another tool used by the suspected Russian hackers behind the SolarWinds campaign. The new tool, “Raindrop,” seems to have been used to spread across networks after initial access. https://symantec-enterprise- blogs.security.com/... https://twitter.com/...
Moar SolarWinds related malware. Really interesting to see how this is all unfolding in the weeks since the attack was first revealed. https://twitter.com/...
Malwarebytes feared it could become the next SolarWinds and spent the last month auditing its software source code -Said there's no sign UNC2452 poisoned any of its apps -Appears intruders only managed to access a few emails https://www.zdnet.com/...
Symantec discovered another malicious component used by SolarWinds hackers. The tool, which they're calling Raindrop, is part of second-stage activity, used only on high-value targets to load CobaltStrike and spread across the victim's network. https://symantec-enterprise- blogs.…