New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

SolarWinds hackers are going after cloud, managed and IT service providers

New York Tech Editorial Team by New York Tech Editorial Team
October 25, 2021
in Cybersecurity
0
SolarWinds hackers are going after cloud, managed and IT service providers
Share on FacebookShare on Twitter

Nobelium, the advanced, persistent threat (APT) actor behind the 2020 SolarWinds supply chain attack that served as a springboard for breaching a variety of high-level targets, is targeting organizations via their various service providers.

targeting service providers

“Nobelium has been attempting to replicate the approach it has used in past attacks by targeting organizations integral to the global IT supply chain. This time, it is attacking a different part of the supply chain: resellers and other technology service providers that customize, deploy and manage cloud services and other technologies on behalf of their customers,” says Tom Burt, Corporate VP, Customer Security & Trust, Microsoft.

“We believe Nobelium ultimately hopes to piggyback on any direct access that resellers may have to their customers’ IT systems and more easily impersonate an organization’s trusted technology partner to gain access to their downstream customers.”

Targeting service providers

According to Microsoft’s threat analysts, Nobelium has been trying to compromise cloud service providers, managed service providers, and other IT services organizations in the US and Europe, to ultimately target government organizations, think tanks, and companies these companies serve.

The threat actor apparently does not leverage product vulnerabilities, but has other tools in their offensive arsenal – malware, password spraying, supply chain attacks, token theft, API abuse, and spear phishing – to steal legitimate credentials and gain privileged access. Oftentimes, Nobelium attackers try different methods and probe several third parties to get access to one specific target (as illustrated in the image above).

Microsoft detected over 140 resellers and technology service providers being targeted by the attackers, but not all attacks were successful.

“We continue to investigate, but to date we believe as many as 14 of these resellers and service providers have been compromised. Fortunately, we have discovered this campaign during its early stages, and we are sharing these developments to help cloud service resellers, technology providers, and their customers take timely steps to help ensure Nobelium is not more successful,” Burt added.

Aside from notifying targeted entities, Microsoft has been working on implementing improvements to help protect technology partners in its supply chain.

The company has also shared attackers’ TTPs, threat hunting queries for detection and investigation, and specific technical guidance for potential targets: service providers, organizations that rely on elevated privileges, and downstream customers.

A nation-state actor?

“Nobelium is frequently observed conducting activities consistent with intelligence collection,” Microsoft pointed out.

The company (and the U.S. government, and other governments) believes Nobelium to be part of Russia’s foreign intelligence service (SVR).

“This recent activity is another indicator that Russia is trying to gain long-term, systematic access to a variety of points in the technology supply chain and establish a mechanism for surveilling – now or in the future – targets of interest to the Russian government,” Burt noted.

Microsoft’s analysts warned that organizations previously targeted by Nobelium should monitor for recurring attacks by the same actor.

Credit: Source link

Previous Post

Local startup to collect compost, capture carbon | Subscriber

Next Post

Hertz reportedly orders 100,000 Teslas in $4.2 billion deal

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
Hertz reportedly orders 100,000 Teslas in $4.2 billion deal

Hertz reportedly orders 100,000 Teslas in $4.2 billion deal

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
10 Raunchy Movies on Netflix You Won’t Regret Watching

10 Raunchy Movies on Netflix You Won’t Regret Watching

May 20, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Clubhouse will soon let you pin links to the top of rooms

Clubhouse will soon let you pin links to the top of rooms

October 23, 2021
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
three men posing outdoors

An AI Company on a Tiny Island Just Beat the Biggest Names on Wall Street. Here’s the Part That Should Surprise You.

June 2, 2026
man in a blue coat wearing glasses

Why Human Skills Matter More Than Ever in the AI Era

May 27, 2026
essential travel gadgets

May 24, 2026
graphic of Next-Gen Entrepreneurs event

Leadership, Judgment, and Innovation: A Post-Event Conversation with Dr. Fang Miao

May 21, 2026
Arito founding team

Arito AI Raises $6 Million To Bring Agentic Intelligence To Finance And Revenue Teams

May 20, 2026
Viewz founding team

Viewz Raises $7M to Retire the Finance Stack as We Know It

May 19, 2026

Recommended

three men posing outdoors

An AI Company on a Tiny Island Just Beat the Biggest Names on Wall Street. Here’s the Part That Should Surprise You.

June 2, 2026
man in a blue coat wearing glasses

Why Human Skills Matter More Than Ever in the AI Era

May 27, 2026
essential travel gadgets

May 24, 2026
graphic of Next-Gen Entrepreneurs event

Leadership, Judgment, and Innovation: A Post-Event Conversation with Dr. Fang Miao

May 21, 2026

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

AI AI QSRs Allseated Automat-it AWS B2B marketing Business CISO CISO Whisperer Collaborations Companies To Watch cryptocurrency Cybersecurity Entrepreneur Fetcherr Finance FINQ Fintech Funding Announcement hi-tech Hi Auto Impala Investing Investors investorsummit Israel israelitech Leaders LinkedIn Leaders Metaverse Mindset Minnesota omri hurwitz PointFive PR QSR Real Estate start- up startupnation Startups Startups On Demand Tech Tech leaders Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media