Stay in the Loop

We are thrilled to extend a warm welcome to you as a valuable member of our vibrant crypto community! Whether you're an experienced trader, a crypto enthusiast, or someone who's just getting started on their digital currency journey, we're excited to have you onboard.

Read & Get Inspired

We're delighted to have you here and embark on this exciting journey into the world of Wikibusiness. Whether you're a newcomer or a seasoned explorer in this realm, we're dedicated to making your experience extraordinary. Our website is your gateway to a treasure trove of knowledge, resources, and opportunities.

PrimeHomeDeco

At PrimeHomeDeco, we believe that your home should be a reflection of your style and personality. Our upcoming website is dedicated to bringing you a curated selection of exquisite home decor that will transform your living spaces into elegant sanctuaries. Whether you're looking to revamp your living room, add a touch of sophistication to your bedroom, or create a cozy and inviting ambiance in your dining area, we have just the right pieces for you.

Massive alleged Russian malware hack hits US through SolarWinds: What you need to know – CNET

eyes-surveillance-security

A Russian hacking campaign has struck several federal agencies, according to security companies and news reports.


Angela Lang/CNET

Earlier this year, hackers compromised software made by a cybersecurity company you might not have heard of. The infiltration led to a massive malware campaign that’s now affecting US federal agencies as well as governments around the world, according to the security firm and news reports.

The hacked company, SolarWinds, sells software that lets an organization see what’s happening on its computer networks. Hackers inserted malicious code into an updated version of the software, called Orion. Around 18,000 SolarWinds customers installed the tainted updates onto their systems, the company said.

The compromised update process has had a sweeping effect, the scale of which keeps growing as new information emerges. Based on newspaper reports, the company’s statements and analysis from other security firms, a Russian intelligence agency reportedly carried out a sophisticated attack that struck several US federal agencies and private companies including Microsoft.  

US national security agencies issued a joint statement Wednesday acknowledging a “significant and ongoing hacking campaign” that’s affecting the federal government. It’s still unclear how many agencies are affected or what information hackers might’ve stolen so far, but by all accounts the malware is extremely powerful. According to analysis by Microsoft and security firm FireEye, both of which were also infected with the malware, it gives hackers broad reach into impacted systems.

On Thursday, Politico reported that systems at the Department of Energy and the National Nuclear Security Administration were also affected. Also on Thursday, Microsoft said it had identified more than 40 customers that were targeted in the hack. More information is likely to emerge about the hack and its aftermath. Here’s what you need to know about the SolarWinds hack:

How did hackers sneak malware into a software update?

Hackers managed to access a system that SolarWinds uses to put together updates to its Orion product, the company explained in a filing with the SEC. From there, they inserted malicious code into otherwise legitimate software updates. This is known as a supply-chain attack, because it infects software while it’s being assembled.

It’s a big coup for hackers to pull off a supply-chain attack, because it packages their malware inside a trusted piece of software. Instead of having to trick individual targets into downloading malicious software with a phishing campaign, the hackers could rely on several government agencies and companies to install the Orion update at SolarWinds’ prompting. 

The approach is especially powerful in this case because hundreds of thousands of companies and government agencies around the world reportedly use the Orion software. With the release of the tainted software update, SolarWinds’ vast customer list became potential hacking targets.

Which government agencies were infected with the malware?

According to reports from Reuters, The Washington Post and The Wall Street Journal, the malware affected the US Homeland Security, Commerce and Treasury Departments. Politico reported on Thursday that nuclear programs run by the US Department of Energy and the National Nuclear Security Administration were also targeted.

It’s still unclear what information, if any, was stolen from the federal agencies, but the amount of access appears to be broad.

Though the Department of Energy and the Commerce Department have acknowledged the hacks to news sources, there’s no official confirmation that other specific federal agencies have been hacked. However, the US Cybersecurity and Infrastructure Security Agency put out an advisory urging federal agencies to mitigate the malware, noting that it’s “currently being exploited by malicious actors.” 

Were private companies or other governments hit with the malware?

Yes. Microsoft confirmed Thursday that it found indicators of the malware in its systems, after confirming Sunday that the breach was affecting customers of its cybersecurity services. A Reuters report also said that Microsoft’s own systems were used to further the hacking campaign, but Microsoft denied this claim to news agencies. On Wednesday, the company began quarantining the versions of Orion known to contain the malware, in order to cut hackers off from its customers’ systems.

FireEye also confirmed last week that it was infected with the malware and was seeing the infection in customer systems as well.

Other than FireEye and Microsoft, it isn’t clear which of SolarWinds’ private sector customers saw malware infections. The company’s customer list includes large corporations, such as AT&T, Procter & Gamble and McDonald’s. The company also counts governments and private companies around the world as customers. FireEye says many of those customers were infected.

What do we know about Russian involvement in the hack?

Unnamed US government officials have reportedly told news outlets that a hacking group widely believed to be a Russian intelligence agency is responsible for the malware campaign. SolarWinds, cybersecurity firms and US government statements have attributed the hack to “nation-state actors” but haven’t named a country directly.

In a statement on Facebook, the Russian embassy in the US denied responsibility for the SolarWinds hacking campaign. “Malicious activities in the information space contradict the principles of the Russian foreign policy, national interests and our understanding of interstate relations,” the embassy said, adding, “Russia does not conduct offensive operations in the cyber domain.”

Nicknamed APT29 or CozyBear, the hacking group named by news reports has previously been blamed for targeting email systems at the State Department and White House during the administration of President Barack Obama. It was also named by US intelligence agencies as one of the groups that infiltrated email systems at the Democratic National Committee in 2015, but the leaking of those emails isn’t attributed to CozyBear. (Another Russian agency was blamed for that.)

More recently, the US, UK and Canada have identified the group as responsible for hacking efforts that tried to access information about COVID-19 vaccine research.

Related articles

Tesla Full Self-Driving lands in a new country, its 7th

Tesla rolled out Full Self-Driving version 14.2 yesterday to members of the Early Access Program (EAP). Expectations were high, and Tesla surely delivered. With the rollout of Tesla FSD v14.2, there were major benchmarks...

Meloo – Music Theme for WordPress

LIVE PREVIEWBUY FOR $59 Meloo is extremely flexible WordPress Music Theme, intuitive and easy to use featuring almost unlimited posts filtering, drag & drop page building, AJAX continuous music playback and more. Meloo theme concept built...

The Overview Effect: Astronaut Perspectives from 25 Years in Low Earth Orbit

To see Earth from space is to be forever changed by the view. Since Alan Shepard became the first American to lay eyes on our home planet from above, countless NASA astronauts have...

Tesla CEO Elon Musk teases insane capabilities of next major FSD update

Tesla CEO Elon Musk teased the insane capabilities of the next major Full Self-Driving update just hours after the company rolled out version 14.2 to owners. Tesla Full Self-Driving v14.2 had some major improvements...
[mwai_chat model="gpt-4"]