/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Malwarebytes says it was hacked by group that breached SolarWinds, via Azure and Office 365 exploits, but attackers only accessed a subset of internal emails

Malwarebytes becomes fourth major security firm targeted by attackers after Microsoft, FireEye, and CrowdStrike.

ZDNet Catalin Cimpanu

Context & Ripple Effects

The SolarWinds incident was already extending beyond Orion-focused investigation: FireEye had released a tool to check for known attacker techniques, while Microsoft disclosed that an employee-account compromise exposed some source code without email access. Malwarebytes adds a security vendor whose exposure was centered on cloud productivity systems and internal mail.

Related coverage also distinguished a separate SolarWinds-targeting group using different malware, making attribution important rather than treating every SolarWinds-related intrusion as one incident.

First-order effects

  • Malwarebytes must investigate the subset of internal email accessed through the Azure and Office 365 compromise and assess what information those mailboxes exposed.
  • Microsoft’s Azure and Office 365 environments become part of the incident-response scope for a campaign already associated with intrusions at Microsoft, FireEye, CrowdStrike, and Malwarebytes.

Second-order effects

  • Security teams using Microsoft cloud identity and email services have a stronger reason to pair SolarWinds-focused checks with review of account access and mailbox exposure, rather than limiting inquiries to Orion systems.
  • FireEye’s network-audit tool gains practical relevance for organizations seeking evidence of the techniques associated with the reported group, while separate-malware reporting keeps detection and attribution work from collapsing into a single signature set.

Third-order effects

  • The pattern points to a supply-chain incident evolving into a broader identity-and-cloud-security problem: security vendors themselves are targets, and post-breach assessments increasingly span software, employee accounts, and hosted communications.
  • If distinct groups continue to exploit the same vendor ecosystem with different malware, defenders and investigators will need to separate campaigns by tactics and access paths rather than organize response solely around the SolarWinds name.

The trend: The SolarWinds episode is becoming a wider campaign narrative in which software supply-chain exposure, cloud account compromise, and attacks on security vendors must be investigated together but attributed separately.

Discussion

  • @campuscodi Catalin Cimpanu on x
    Intrusion did not take place via a trojanized Orion app, since Malwarebytes doesn't use the software -Point of entry was described as “exploited an Azure Active Directory weakness” -Malwarebytes said it learned of the hack from Microsoft last month https://www.zdnet.com/...
  • @threatintel Threat Intelligence on x
    More information from our SolarWinds investigation. New tool - Raindrop - appears to have been used by attackers for spreading across victim networks. https://symantec-enterprise- blogs.security.com/... #SolarWinds #Raindrop #Sunburst https://twitter.com/...
  • @arekfurt Brian on x
    “The investigation indicates the attackers leveraged a dormant email protection product within our Office 365 tenant that allowed access to a limited subset of internal company emails.” Okay, so tell us the “email protection product” that was compromised. https://blog.malwarebyte…
  • @k8em0 Katie Moussouris on x
    “While Teardrop was used on computers that had been infected by the original Sunburst Trojan, Raindrop appeared elsewhere on the network, being used by the attackers to move laterally & deploy payloads on other computers” 🎶Raindrops keep fallin on my head(of incident response)🎶 h…
  • @fabio_viggiani Fabio Viggiani on x
    Ah! I had an early feeling of malicious O365 apps used by this threat actor, before we got to know about Solarwinds Orion. Turns out that O365 apps were also used, for targets without Orion: https://www.zdnet.com/... https://twitter.com/...
  • @ericgeller Eric Geller on x
    Symantec has discovered another tool used by the suspected Russian hackers behind the SolarWinds campaign. The new tool, “Raindrop,” seems to have been used to spread across networks after initial access. https://symantec-enterprise- blogs.security.com/... https://twitter.com/...
  • @nickdothutton Nick Hutton on x
    “threat actor added a self-signed certificate with credentials to the service principal account.” https://blog.malwarebytes.com/ ...
  • @selenalarson Selena on x
    Moar SolarWinds related malware. Really interesting to see how this is all unfolding in the weeks since the attack was first revealed. https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    Malwarebytes feared it could become the next SolarWinds and spent the last month auditing its software source code -Said there's no sign UNC2452 poisoned any of its apps -Appears intruders only managed to access a few emails https://www.zdnet.com/...
  • @kimzetter Kim Zetter on x
    Symantec discovered another malicious component used by SolarWinds hackers. The tool, which they're calling Raindrop, is part of second-stage activity, used only on high-value targets to load CobaltStrike and spread across the victim's network. https://symantec-enterprise- blogs.…