Estimated Reading Time: 3
Microsoft Corp said on Thursday it found malicious software in its systems related to a massive hacking campaign disclosed by U.S. officials this week, adding a top technology target to a growing list of attacked government agencies.
The Redmond, Washington company is a user of Orion, the widely deployed networking management software from SolarWinds Corp which was used in the suspected Russian attacks on vital U.S. agencies and others.
Microsoft also had its own products leveraged to attack victims, said people familiar with the matter.
The U.S. National Security Agency issued a rare “cybersecurity advisory” Thursday detailing how certain Microsoft Azure cloud services may have been compromised by hackers and directing users to lock down their systems.
“Like other SolarWinds customers, we have been actively looking for indicators of this actor and can confirm that we detected malicious Solar Winds binaries in our environment, which we isolated and removed,” a Microsoft spokesperson said, adding that the company had found “no indications that our systems were used to attack others.”
One of the people familiar with the hacking spree said the hackers made use of Microsoft cloud offerings while avoiding Microsoft’s corporate infrastructure.
Microsoft did not immediately respond to questions about the technique.
Still, another person familiar with the matter said the Department of Homeland Security (DHS) does not believe Microsoft was a key avenue of fresh infection.
Both Microsoft and the DHS, which earlier on Thursday said the hackers used multiple methods of entry, are continuing to investigate.
The FBI and other agencies have scheduled a classified briefing for members of Congress Friday.
CISA said it was continuing to analyze the other avenues used by the attackers.
So far, the hackers are known to have at least monitored email or other data within the U.S. departments of Defense, State, Treasury, Homeland Security and Commerce.
As many as 18,000 Orion customers downloaded the updates that contained a back door, SolarWinds has said.
Since the campaign was discovered, software companies have cut off communication from those back doors to the computers maintained by the hackers.
But the attackers might have installed additional ways of maintaining access, CISA said, in what some have called the biggest hack in a decade.
The Department of Justice, FBI and Defense Department, among others, have moved routine communication onto classified networks that are believed not to have been breached, according to two people briefed on the measures.
They are assuming that the non-classified networks have been accessed, the people said.
CISA and private companies including FireEye Inc, which was the first to discover and reveal it had been hacked, have released a series of clues for organizations to look for to see if they have been hit.
But the attackers are very careful and have deleted logs, or electronic footprints or which files they have accessed, security experts said. That makes it hard to know what has been taken.
Some major companies have said they have “no evidence” that they were penetrated, but in some cases that may only be because the evidence was removed.
In most networks, the attackers would also have been able to create false data, but so far it appears they were interested only in obtaining real data, people tracking the probes said.
Meanwhile, members of Congress are demanding more information about what may have been taken and how, along with who was behind it.
The House Homeland Security Committee and Oversight Committee announced an investigation Thursday, while senators pressed to learn whether individual tax information was obtained.
In a statement, President-elect Joe Biden said he would “elevate cybersecurity as an imperative across the government” and “disrupt and deter our adversaries” from undertaking such major hacks.
- Lagos govt says negotiations are ongoing with manufacturers to make COVID-19 vaccines available
- “Scammers bent on defrauding job seekers” -EFCC raise alert
- Just In: Nigeria orders immediate closure of enrollment activities at NIMC Headquarters
- Nigerian Military decimate Boko Haram camp in Borno
- Borno state Governor says south-easterners should negotiate for power rather than expect others to leave it for them
- Islamic State terrorists raid Nigeria’s military base in Marte, Borno
- ..had gone to the pharmacy to buy medicine …..How Gunmen abduct Imo State University lecturer
- Lagos Government releases work-from-home directive; Grade 14 & below to resume Feb 1
- Yoweri Museveni of Uganda wins 6th term re-election
- Rovers of Calabar to square up against 3SC in NNL season opening match