/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Microsoft says the Russian-backed Nobelium group, responsible for the SolarWinds hack, is still targeting global IT supply chain with 14 breaches since May 2021

Microsoft says the Russian-backed Nobelium threat group behind last year's SolarWinds hack is still targeting the global IT supply chain … Source: Microsoft On the Issues .

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

Microsoft had already described SolarWinds as an ongoing campaign that reached more than 40 customers, and later tied the same actors to a malicious-email campaign through a State Department aid agency targeting 150 organizations. The new disclosure shifts the focus from individual victims to IT providers as the route into many downstream networks.

The report also reinforces Microsoft’s earlier call for a global response to the SolarWinds intrusion: compromise of a supplier can extend an attacker’s reach well beyond the initial breach.

First-order effects

  • The 14 breached IT providers become immediate pivot points for Nobelium’s access to their customers, raising the urgency of incident review across those providers’ connected environments.
  • Microsoft’s disclosure gives customers and security teams a concrete reason to scrutinize supplier-originated software, services, and communications rather than treating SolarWinds as a closed incident.

Second-order effects

  • Organizations that depend on affected IT providers face a broader third-party security burden, because the earlier aid-agency email campaign showed how a compromised intermediary can be used to reach many outside groups.
  • IT suppliers face greater pressure to demonstrate control over their software-delivery and customer-access paths as buyers reassess the risk concentrated in shared providers.

Third-order effects

  • Repeated use of trusted intermediaries points toward software and IT-service delivery becoming a primary security control plane, where supplier assurance matters as much as perimeter defense.
  • If this pattern persists, supply-chain resilience will increasingly depend on traceable control over how software, updates, and provider access reach customer networks.

The trend: Nobelium’s reported activity is part of a broader shift in which attackers target high-leverage IT suppliers to scale access across customer ecosystems.

Discussion

  • @msftsecurity @msftsecurity on x
    The latest activity from #NOBELIUM indicates the Russian nation-state actor is trying to gain long-term systematic access to various points in the technology supply chain and establish a mechanism for surveilling targets of interest. https://blogs.microsoft.com/ ...
  • @carlquintanilla Carl Quintanilla on x
    “While we are clear-eyed that nation-states, including Russia, will not stop attacks like these overnight, we believe steps like the cybersecurity executive order in the U.S., .. have put us all in a much better position to defend against them.” $MSFT https://blogs.microsoft.com/…
  • @ericgeller Eric Geller on x
    New: The Russian hackers behind the massive SolarWinds campaign have continued their supply chain attacks by targeting “more than 140 resellers and technology service providers” since May, according to Microsoft. ~14 targets compromised. https://blogs.microsoft.com/ ...
  • @thegrugq Thaddeus E. Grugq on x
    This is a huge deal. The SVR is doing their job and that's completely unacceptable. The Russians are using their own CIA to steal secrets from governments. Absolutely disgusting!! https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    IOCs for the masses: https://www.microsoft.com/... https://twitter.com/...
  • @thegrugq Thaddeus E. Grugq on x
    .@halvarflake predicted it years ago. Why are the Russians so slow to adopt good strategy? https://twitter.com/...