A look at Positive Technologies, a Russian cybersecurity firm sanctioned by the US, which sources say provides hacking tools and ops support for Russian spies
Washington has sanctioned Russian cybersecurity firm Positive Technologies. US intelligence reports claim it provides hacking tools and runs operations for the Kremlin.
MIT Technology Review Patrick Howell O'Neill
Context & Ripple Effects
Washington’s action places Positive Technologies in an established sanctions approach: the Treasury had previously targeted Russian people and firms over alleged cyberattack support. The allegation here extends that logic to a commercial cybersecurity vendor said to supply tools and operational assistance to Russian intelligence.
The immediate ecosystem split is already visible: Microsoft removed Positive from its early-access vulnerability-information program, while IBM still listed it as a security partner. That makes vendor trust and access to sensitive security coordination the practical issue, not only the sanctions designation.
First-order effects
- Positive Technologies loses standing with U.S. institutions and faces an immediate loss of Microsoft early vulnerability access, limiting its role in a key security-vendor information channel.
- Microsoft’s removal draws a clear trusted-vendor boundary around Positive, while IBM’s listed partnership exposes the need for partners to reassess their association with the sanctioned firm.
Second-order effects
- Other software and security providers that share pre-release vulnerability intelligence face pressure to apply comparable screening to vendors alleged to support state espionage.
- Customers and partners of Positive Technologies must weigh whether security relationships with the firm create operational and reputational exposure as Washington treats alleged cyber-support services as sanctionable conduct.
Third-order effects
- The episode points toward a more formal separation between globally integrated cybersecurity supply chains and vendors viewed by the U.S. as aligned with state intelligence operations.
- If this enforcement pattern persists, sanctions and access to vulnerability-coordination programs will increasingly operate together as tools for policing the boundary between commercial security work and state-backed cyber activity.
The trend: Cybersecurity vendors are being judged not only by their products but by whether their tools, access, and operations are seen as compatible with state intelligence activity.
Related: Trusted-tool boundary · Dual-use code intelligence · Positive Technologies · Microsoft removes Positive from early vulnerability access · US sanctions Russian cyberattack support
Related Coverage
- NSA, FBI, DHS expose Russian intelligence hacking tradecraft CyberScoop · Shannon Vavra
- View article Zero Day
- View article National Security …
- View article Associated Press
- Executive Order on Blocking Property with Respect to Specified Harmful Foreign Activities of the Government of the Russian Federation The White House
- View article Positive Technologies
- SolarWinds Hack - US officially Blames Russian Intel Agency Hackers HackRead · Waqas
- US Government Sanctions Crypto Addresses Linked to Russian Election Fraud Scheme CoinDesk · Nikhilesh De
- Biden Admin Names 6 Russian Tech Firms Aiding Gov't Hackers CRN · Michael Novinson
- As US takes sweeping action against Russia for years of hacking, industry skeptical of impact SC Media · Derek B. Johnson
- Biden calls out crypto's use in sanctions evasion in executive order response to Russian cyberattacks The Block · Kollen Post
- It was Russia wot did it: SolarWinds hack was done by Kremlin's APT29 crew, say UK and US The Register · Gareth Corfield
- US government confirms Russian SVR behind the SolarWinds hack BleepingComputer · Ionut Ilascu
- Treasury Sanctions Russia with Sweeping New Sanctions Authority U.S. Department of the Treasury
- White House formally blames Russian intelligence service SVR for SolarWinds hack The Record · Catalin Cimpanu
- FACT SHEET: Imposing Costs for Harmful Foreign Activities by the Russian Government The White House
- Treasury Escalates Sanctions Against the Russian Government's Attempts to Influence U.S. Elections U.S. Department of the Treasury
- US sanctions Russian government, security firms for SolarWinds breach, election interference CSO · Cynthia Brumfield
- US Sanctions on Russia Rewrite Cyberespionage's Rules Wired · Andy Greenberg
- How the Kremlin provides a safe harbor for ransomware Associated Press · Frank Bajak
- NSA: Top 5 vulnerabilities actively abused by Russian govt hackers BleepingComputer · Lawrence Abrams
- North Atlantic Council Statement following the announcement by the United States of actions with regard to Russia NATO
- Pakistan Firm Sold Fake KYC Docs to Russian Trolls for Bitcoin: US Treasury Decrypt · Jeff Benson
- Biden administration imposes significant economic sanctions on Russia over cyberspying, efforts to influence presidential election Washington Post · Ellen Nakashima
- Russian Foreign Intelligence Service Exploiting Five Publicly Known Vulnerabilities to Compromise U.S. and Allied Networks Federal Bureau of Investigation
- U.S. government accuses Russian companies of recruiting spies, hacking for Moscow CyberScoop · Shannon Vavra
- The Hack Roundup: White House Sanctions Russia over SolarWinds Nextgov · Mariam Baksh
- US Formally Attributes SolarWinds Attack to Russian Intelligence Agency Dark Reading · Jai Vijayan
- Six key takeaways from Biden's Russia sanctions announcement CNN
- U.S. Exposes Hackers' Helpers to Punish Russian Attacks Bloomberg
- U.S. imposes sanctions on Russia over election interference, SolarWinds hack SiliconANGLE · Maria Deutscher
- Biden imposes new sanctions on Russia in response to election interference and cyber hacks CNN
- US hits Russia with sanctions following SolarWinds cyberattack TechRadar · Anthony Spadafora
- US expels Russian diplomats, imposes new round of sanctions Associated Press
Discussion
-
Vox
Sara Morrison
on x
Biden makes good on his promise to punish Russia for the massive SolarWinds hack
-
@howelloneill
Patrick Howell O'Neill
on x
Scoop: Previously unreported US intelligence assessments say Positive Technologies provides hacking tools, knowledge, and operations for the Russian government https://www.technologyreview.com/ ...
-
@dellcam
Dell Cameron
on x
Scoop by @HowellONeill: Previously unreported US intelligence assessments say Positive Technologies, a cyber firm just sanctioned by U.S. Treasury, is a major provider of “offensive hacking tools, knowledge, and even operations to Russian spies.” https://www.technologyreview.com/…
-
@maxbergmann
Max Bergmann
on x
Second, while the WH did not sanction any oligarchs, it did send a clear message by defining what it sees as Russian interference. For ex, it clearly states that adult children of those interfering are fair game. That has to catch oligarch's attention. 5/ https://www.whitehouse.g…
-
@ericgeller
Eric Geller
on x
Quite the scoop here from @HowellONeill on newly sanctioned Russian company Positive Technologies: “[A]ccording to previously unreported US intelligence assessments, it also develops and sells weaponized software exploits to the Russian government.” https://www.technologyreview.c…
-
@hatr
Hakan
on x
“Positive did not just discover and publicize flaws in the system, but also developed offensive hacking capabilities to exploit security holes that were then used by Russian intelligence in cyber campaigns”, the U.S. has concluded https://www.technologyreview.com/ ...
-
@howelloneill
Patrick Howell O'Neill
on x
New: US sanctions against the Russian cybersecurity firm Positive Technologies are privately supported by US intelligence assessments which claim it provides hacking tools and runs operations for the Kremlin. https://www.technologyreview.com/ ...
-
@nsacyber
@nsacyber
on x
Russian Foreign Intelligence Service (SVR) cyber actors are exploiting five publicly known vulnerabilities to target U.S. and allied critical networks. Review our joint #cybersecurity guidance with @CISAgov and @FBI and apply the mitigations to stop them: https://www.nsa.gov/... …
-
@selenalarson
Selena
on x
today's sanctions confirmed what many people suspected: fsb working with evil corp https://home.treasury.gov/... https://twitter.com/...
-
@ministerblok
Stef Blok
on x
NL expresses its solidarity with the US on the impact of malicious cyber operations, notably the SolarWinds-hack. NL continues to cooperate with the US to promote a free, open and secure internet. https://twitter.com/...
-
@francediplo_en
France Diplomacy
on x
Cyberattack against #SolarWinds: alongside @NATO Allies and 🇪🇺 member states, 🇫🇷 expresses its solidarity with the 🇺🇸. 🇫🇷 reiterates its continuous engagement to promote a non-fragmented, open, secured and free cyberspace. →https://www.nato.int/... →https://www.consilium.europa.e…
-
@eucouncilpress
EU Council Press
on x
Declaration of @JosepBorrellF on behalf of the EU 🇪🇺expressing solidarity with the US 🇺🇸 on the impact of the SolarWinds cyber operation. The EU is strongly committed to a global, open and secure cyberspace respecting human rights & fundamental freedoms https://www.consilium.euro…
-
@michaeldweiss
Michael Weiss
on x
Treasury sanctions a bunch of RIS-run disinformation portals including InfoRos, a GRU cut-out. https://home.treasury.gov/... https://twitter.com/...
-
@jimsciutto
Jim Sciutto
on x
Imagine a Trump tweet now alleging it may really have been China and then a deliberate skewing of the Intel by political appointees at ODNI to back up the tweet. (PS: this happened). https://twitter.com/...
-
@kimmasters
Kim Masters
on x
The hoax was calling it a hoax. https://twitter.com/...
-
@martinmatishak
Martin Matishak
on x
On a call today , @RGB_Lights said the companies named in the suite of sanction were there because they “provide a range of services to the SVR, from providing the expertise to developing tools, supplying infrastructure and even, sometimes, operationally supporting activities.” h…
-
@wakeywakey16
This Historically Engineered Moment
on x
Gee, if only the govt was successful in dismantling Cozy Bear back in 2014-2015 when they were tearing up the upper level of our govt systems. Or when they were in the DNC for over a year while Crowdstrike watched. “Wait! Let's see what they do with the intel they are stealing” h…
-
@petestrzok
Peter Strzok
on x
Confirms our suspicions- Direct line from the campaign to Kilimnik to Russian intel. “During the 2016 U.S. presidential election campaign, Kilimnik provided the Russian Intelligence Services with sensitive information on polling and campaign strategy.” https://home.treasury.gov/.…
-
@saysdana
@saysdana
on x
I'm so thankful I haven't used Kaspersky software for at least 15 years now. https://twitter.com/...
-
@gossithedog
Kevin Beaumont
on x
Worth looking at when Positive Technologies have been dropping some big enterprise vulns publicly, in terms of US holiday dates. https://twitter.com/...
-
@dnvolz
Dustin Volz
on x
Some U.S. officials advised against sanctions specifically justified on the SolarWinds hack, as it could open up the U.S. to foreign censure for its own activities. “SVR was stealing things, not breaking things or spreading disinformation,” said @RidT. https://www.wsj.com/...
-
@jennamc_laugh
Jenna McLaughlin
on x
NSA, CISA, and FBI are formally attributing the SolarWinds breach to Russia's SVR: https://www.nsa.gov/... https://twitter.com/...
-
@profwoodward
Alan Woodward
on x
Russia has a narrow window to stop this behaviour or it's going to become isolated - that's not good for anyone as we will end up in Cold War 2.0 and I can't imagine it'll be any more fun that the original https://media.defense.gov/... https://twitter.com/...
-
@iblametom
Thomas Brewster
on x
NSA/FBI/CISA say Russia is exploiting various VPNs and single sign-on tools from massive vendors... not a surprise given the rise in homeworking in the pandemic. https://www.nsa.gov/...
-
@gordoncorera
Gordon Corera
on x
“US poised to impose sanctions on Russia for cyber-attacks” - There's been back and forth about these sanctions, partly it seems over whether to separate out issues like cyber or encompass everything. Looks like washington opting for max impact https://www.bbc.com/...
-
@dfriedman33
Dan Friedman
on x
In new sanctions on Russia, Treasury bars U.S. banks from lending to key Russian gov institutions. That's a response to actions Russia took while facing (narrower) sanctions. Seems certain US will need better diplomacy too to change Kremlin's behavior. https://home.treasury.gov/.…
-
@peterzeihan
Peter Zeihan
on x
The Biden administration just announced it's going after pretty much every Russian cyber misinformation arm that it is aware of globally. https://home.treasury.gov/...
-
@selectedwisdom
Clint Watts
on x
After many years, USG has started taking action against Russia's disinformation machine. A long over due move and a good one. https://home.treasury.gov/...
-
@usembassykyiv
U.S. Embassy Kyiv
on x
Today, the U.S. Department of the Treasury took multiple sanctions actions under new and existing Executive Orders (E.O.) targeting aggressive and harmful activities by the Government of the Russian Federation. https://home.treasury.gov/...
-
@timobrien
Tim O'Brien
on x
Of all the sanctions Biden is planning to impose on Russia for cyber-hacking, Navalny, et al, kneecapping Russian debt markets might have the most immediate and visible impact. https://www.whitehouse.gov/...
-
@natashabertrand
Natasha Bertrand
on x
As we first reported yesterday morning, the admin is PNGing Russian diplomats (spies). “The US is expelling ten personnel from the Russian diplomatic mission in Washington, DC. The personnel include representatives of Russian intelligence services.” https://www.whitehouse.gov/...
-
@wylienewmark
@wylienewmark
on x
I can't recall a previous set of cyber-related sanctions against Russia that goes quite so deep into the public-private overlaps in how Russian intelligence engages in cyber operations. https://home.treasury.gov/...
-
@x0rz
@x0rz
on x
Russia knows that ransomware are crippling western countries and incident response capacity are maxed. IMO, this is not a side effect but a strategic will: while you're busy responding to cybercrime, cyber espionage operations are quietly continuing... https://twitter.com/...
-
@bing_chris
Chris Bing
on x
Treasury sanctions 5 Russian cybersecurity firms which they say support RU intelligence agencies: https://home.treasury.gov/... List includes: -Positive Technologies -ERA technologies/Pasit -SVA -Neobit -Advanced System Technologies
-
@brfreed
Benjamin Freed
on x
Evil Corp is behind some ransomware types like WastedLocker, victims of which include navigational and fitness tech maker Garmin. https://www.cyberscoop.com/... https://twitter.com/...
-
@thegrugq
Thaddeus E. Grugq
on x
Looks like the end of PHdays. The US sanctions on Positive Technologies will make it a bit hard to pay to attend, and “recruiting event for the FSB and GRU” is not a ringing endorsement. https://home.treasury.gov/... https://twitter.com/...
-
@breakingnews
@breakingnews
on x
U.S. set to hit Russia with fresh sanctions on Thursday for alleged interference in the 2020 presidential election and for a cyberattack against the American government, according to a U.S. official and a second source familiar with the matter. https://www.nbcnews.com/...
-
@iblametom
Thomas Brewster
on x
Woah - Positive Technologies, a major cybersecurity company in Russia, is one of those targeted by the Biden regime's efforts against Russian cyber activities. The Treasury is saying Positive has been supporting Russian intelligence: https://home.treasury.gov/...
-
@iblametom
Thomas Brewster
on x
Positive is also accused of running “large-scale conventions that are used as recruiting events for the FSB and GRU.” https://twitter.com/...
-
@kevincollier
Kevin Collier
on x
It's somehow both common knowledge but rarely sourced that Russia not only lets its ransomware operators get away with international crime but also conscripts them for intelligence operations. But here's a data point for that: https://twitter.com/...
-
@craigcaplan
Craig Caplan
on x
April 15, 2021: “Treasury Sanctions Russia with Sweeping New Sanctions Authority” Treasury Secretary Janet Yellen: “The President signed this sweeping new authority to confront Russia's continued and growing malign behavior.” https://home.treasury.gov/...
-
@ridt
Thomas Rid
on x
A lot to digest here. But one thing is already clear: today is a huge, precedent-setting day for attributing Russian intelligence operations, both cyber operations narrowly defined, but also influence operations and active measures. From the U.S. Treasury https://home.treasury.go…