Russian hackers behind fresh US cyberattack, says Microsoft

Published October 26, 2021
A Microsoft logo is seen on an office building in New York City, US on July 28, 2015. — Reuters/File
A Microsoft logo is seen on an office building in New York City, US on July 28, 2015. — Reuters/File

WASHINGTON: The state-backed Russian hacking group that carried out last year’s massive SolarWinds cyberattacks is behind a new and ongoing assault against US and European targets, Microsoft said on Monday.

The software giant’s Threat Intelligence Centre (MSTIC) said in a blog post that the Nobelium group was attempting to gain access to customers of cloud computing services and other IT service providers to infiltrate “the governments, think tanks, and other companies they serve”.

Describing the cyberattack as “nation-state activity”, MSTIC said it “shares the hallmarks” of the assault on SolarWinds, a Texas-based software company targeted as its 300,000-strong customer base gave the hackers access to a huge number of companies.

“It appears the widespread SolarWinds Russia-linked hackers from last year’s attack are again on the hunt for sensitive data and stepping up supply chain attacks across the board,” Wedbush analyst Dan Ives said in a note to investors.

Washington imposed sanctions in April and expelled Russian diplomats in retaliation for Moscow’s alleged involvement in the SolarWinds attack, as well as election interference and other hostile activity.

The latest attack has been underway since at least May, MSTIC said, with Nobelium deploying a “diverse and dynamic toolkit that includes sophisticated malware”.

“Nobelium has been attempting to replicate the approach it has used in past attacks by targeting organizations integral to the global IT supply chain,” Microsoft vice president Tom Burt wrote in a blog post published late Sunday.

This time, Burt noted, Nobelium is targeting “resellers” — companies that customise Microsoft’s cloud computing services for use by businesses and other organisations.

“Since May, we have notified more than 140 resellers and technology service providers that have been targeted by Nobelium,” he wrote.

Published in Dawn, October 26th, 2021

Opinion

Predatory taxation

Predatory taxation

Without fundamental rethink and reset, Pakistan’s catastrophic tax regime will drive the country's already shrinking formal sector towards extinction.

Editorial

Victim complex
Updated 20 Mar, 2025

Victim complex

If New Delhi is sincere about bringing peace to South Asia, let it agree to an unconditional dialogue with Islamabad about all irritants.
LSM decline
20 Mar, 2025

LSM decline

THE slump in large-scale manufacturing amidst the adjustments the economy is forced to make in order to stay afloat...
Education interrupted
20 Mar, 2025

Education interrupted

THE sudden closure of major universities in Balochistan, ostensibly due to ‘security concerns’, marks another...
Genocide resumes
Updated 19 Mar, 2025

Genocide resumes

It appears that Palestinian people will again be left defenceless in the face of merciless brutality.
Strength in unity
19 Mar, 2025

Strength in unity

WILL it count as an opportunity lost? Given the sharp escalation in militant violence in recent weeks, some had ...
NFC weightage
19 Mar, 2025

NFC weightage

THE NFC Award has long been in need of an overhaul. The government’s proposal to bring down the weightage of...