Microsoft says SolarWinds hackers seized an email system used by State Department's international aid agency to breach NGOs and organizations critical of Putin
Microsoft reported that it had detected the intrusion and that the same hackers behind the earlier SolarWinds attack were responsible.
New York Times
Context & Ripple Effects
Microsoft had previously said the SolarWinds-linked group gained access through an employee account but could view only some source code, not alter it or access email. The new incident marks a more operational use of compromised access: a government aid agency's mail system became a channel for malicious messages.
Related coverage identifies roughly 150 recipient organizations and includes NGOs critical of Putin, making the campaign notable not just for access to a government system but for the credibility that system lends to targeted email.
First-order effects
The State Department aid agency and the organizations that received the messages must treat emails from the compromised system as potentially malicious and investigate exposure.
Microsoft's detection publicly attributes the activity to the SolarWinds-linked group, extending the consequences of the earlier employee-account compromise from source-code visibility to email-based targeting.
Second-order effects
NGOs and other politically sensitive organizations face a higher verification burden for messages that appear to originate from trusted government channels.
The State Department's aid operations face a credibility problem with external partners: a compromised sending system can weaken trust in legitimate outreach as well as deliver malicious code.
Third-order effects
If state-linked actors repeatedly convert trusted institutional mail systems into delivery infrastructure, email security shifts from protecting a single organization's inboxes to protecting the trust relationships between governments and their partner networks.
The trend: The SolarWinds campaign illustrates a broader shift from covert access to using compromised trusted systems as scalable channels for targeted influence and intrusion.
There are so many layers to the latest phishing campaign from NOBELIUM. Let's start with the breadth “3,000 individual accounts across more than 150 organizations” And the techniques URL -> ISO (don't see that every day) -> LNK disguised as a folder -> Custom CS Beacon Loader htt…
NEW: Russian gov-linked hackers seized a @ConstantContact account used by @USAID & targeted thousands with malware, like human rights groups critical of Putin. Great to see @msstic & @MsftSecIntel rapidly & publicly attributing this. https://www.microsoft.com/... https://twitter.…
Microsoft says hackers leveraged legit mass-mailing service Constant Contact in this campaign and that due to volume “automated email threat detection systems blocked most of the malicious emails and marked them as spam.” https://www.microsoft.com/...
Microsoft says in a security bulletin that the SolarWinds hackers are behind a new “wide-scale malicious email campaign” targeting 3,000 individual accounts across more than 150 organizations that used “unique infrastructure and tooling for each target.” https://www.microsoft.com…
“Nobelium, originating from Russia, is the same actor behind the attacks on SolarWinds customers in 2020...Nobelium launched this week's attacks by gaining access to the Constant Contact account of USAID.” https://blogs.microsoft.com/ ...
What we know about the latest Russian hacks that used @USAID emails to target more than 150 organizations, including human rights and humanitarian orgs, @Microsoft says. The same SVR hackers that carried out the SolarWinds breach are being blamed. https://blogs.microsoft.com/ ...…
New #sanctions aren't enough. The US and our allies must act boldly to put a stop to the continued cyberwarfare being waged by #Russia, #China, and other adversaries. Far past time to put our offensive cyber capabilities to work.😎 https://twitter.com/...
Volexity researchers write about the same phishing email campaign as reported by Microsoft. They believe the APT29 threat actor is likely responsible for it. https://www.volexity.com/... https://twitter.com/...
Microsoft has released information on a widespread malicious email campaign carried out by a cyber actor they identify as NOBELIUM. See https://us-cert.cisa.gov/... #Cybersecurity #InfoSec
This week the nation-state actor Nobelium launched cyberattacks targeting more than 150 organizations in at least 24 countries. These attacks are only escalating - gov'ts and the private sector must do more to address. https://blogs.microsoft.com/ ...