The Union Democrat

Hacking spree by suspected Russians included US think tank

- By JAMIE TARABAY

The suspected Russian hackers behind a global campaign of cyberattac­ks that have breached U.S. government agencies also hit an American think tank, according to a cybersecur­ity firm that has been fighting them off.

For the better part of a year, investigat­ors at Volexity have been battling hackers that they have dubbed “Dark Halo,” according to the company's president, Steven Adair. He said the hackers have made three attempts to access emails at one of its customers, a U.S. based think tank, which he declined to name.

“This is a threat actor where on multiple occasions we've battled them out of a network only to find them returning because of a new vulnerabil­ity and do some tricks to try and stay under the radar or otherwise get access back to the network to be removed again and then come back a third time,” Adair said.

In the most recent attack, hackers used the same vulnerabil­ity in Solarwinds software that was cited in breaches on U.S. government agencies. In addition to the Department of Homeland Security, Treasury and Commerce, the State Department and the National Institutes of Health were also breached, The Washington Post reported. The hacking campaign also included an attack on the cybersecur­ity firm Fireeye Inc.

That vulnerabil­ity was installed by hackers in the company's legitimate updates to its widely used Orion software, which could allow them to compromise the servers on which its running, according to a statement from Solarwinds. The company said as many as 18,000 customers had installed the malicious update, meaning the networks are infected but haven't necessaril­y been hacked.

Investigat­ors have accounted for “dozens” of victims of the targeted campaign, said Charles Carmakal, senior vice president and chief technical officer at Mandiant, Fireeye's incident response arm. The attackers targeted and compromise­d “high value targets, both government and commercial entities,” he said.

A notorious hacking group tied to the Russian government, APT 29, is a prime suspect in the attacks. The group is also known as Cozy Bear and “the Dukes,” and while Volexity calls it “Dark Halo,” Adair said they believe it is the same group of hackers that attacked government agencies. A spokesman for the Kremlin denied the allegation.

Volexity's account appears to be the first confirmati­on that the tampered Solarwind software was used in an attack outside the U.S. government or Fireeye, the cybersecur­ity firm that first discovered it. It's an indication that the hackers may be using the vulnerabil­ity against a wider range of targets, including think tanks.

Solarwind clients around the world are combing their networks for any trace of the hackers, which could increase the number of known victims in the coming days. Bloomberg News contacted dozens of companies identified by Solarwinds on its website as customers. Many that responded, including Ericsson, Siemens AG and Swisscom AG, said they were investigat­ing whether they were impacted.

Volexity worked on the breaches at the think tank in late 2019 and 2020, according to a blog post published Monday.

Newspapers in English

Newspapers from United States