Hackers used SolarWinds' dominance against it in sprawling spy campaign
Skip to main content
  • Home
  • Economy
  • Stocks
  • Analysis
  • World+Biz
  • Sports
  • Splash
  • Features
  • Videos
  • Long Read
  • Games
  • Epaper
  • More
    • COVID-19
    • Bangladesh
    • Infograph
    • Interviews
    • Offbeat
    • Thoughts
    • Podcast
    • Quiz
    • Tech
    • Subscribe
    • Archive
    • Trial By Trivia
    • Magazine
    • Supplement
  • বাংলা
The Business Standard
WEDNESDAY, MAY 25, 2022
WEDNESDAY, MAY 25, 2022
  • Home
  • Economy
  • Stocks
  • Analysis
  • World+Biz
  • Sports
  • Splash
  • Features
  • Videos
  • Long Read
  • Games
  • Epaper
  • More
    • COVID-19
    • Bangladesh
    • Infograph
    • Interviews
    • Offbeat
    • Thoughts
    • Podcast
    • Quiz
    • Tech
    • Subscribe
    • Archive
    • Trial By Trivia
    • Magazine
    • Supplement
  • বাংলা
Hackers used SolarWinds' dominance against it in sprawling spy campaign

Tech

Reuters
16 December, 2020, 07:00 pm
Last modified: 16 December, 2020, 07:09 pm

Related News

  • Espionage-focused hacker group, Bitter APT, allegedly targets RAB
  • Hackers interrupt briefing by lawyers for those killed in airliner downed by Iran
  • Hackers compromise FBI email system, send thousands of messages
  • Hackers of SolarWinds stole data on US sanctions policy, intelligence probes
  • Wide-ranging SolarWinds probe sparks fear in Corporate America

Hackers used SolarWinds' dominance against it in sprawling spy campaign

Cybersecurity experts are still struggling to understand the scope of the damage

Reuters
16 December, 2020, 07:00 pm
Last modified: 16 December, 2020, 07:09 pm
Hackers used SolarWinds' dominance against it in sprawling spy campaign

On an earnings call two months ago, SolarWinds Chief Executive Kevin Thompson touted how far the company had gone during his 11 years at the helm.

There was not a database or an IT deployment model out there to which his Austin, Texas-based company did not provide some level of monitoring or management, he told analysts on the Oct. 27 call.

"We don't think anyone else in the market is really even close in terms of the breadth of coverage we have," he said. "We manage everyone's network gear."

Now that dominance has become a liability - an example of how the workhorse software that helps glue organizations together can turn toxic when it is subverted by sophisticated hackers.

On Monday, SolarWinds confirmed that Orion - its flagship network management software - had served as the unwitting conduit for a sprawling international cyberespionage operation. The hackers inserted malicious code into Orion software updates pushed out to nearly 18,000 customers.

And while the number of affected organizations is thought to be much more modest, the hackers have already parlayed their access into consequential breaches at the US Treasury and Department of Commerce.

Three people familiar with the investigation have told Reuters that Russia is a top suspect, although others familiar with the inquiry have said it is still too early to tell.

A SolarWinds representative, Ryan Toohey, said he would not be making executives available for comment. He did not provide on-the-record answers to questions sent via email.

In a statement issued Sunday, the company said "we strive to implement and maintain appropriate administrative, physical, and technical safeguards, security processes, procedures, and standards designed to protect our customers."

Cybersecurity experts are still struggling to understand the scope of the damage.

The malicious updates - sent between March and June, when America was hunkering down to weather the first wave of coronavirus infections - was "perfect timing for a perfect storm," said Kim Peretti, who co-chairs Atlanta-based law firm Alston & Bird's cybersecurity preparedness and response team.

Assessing the damage would be difficult, she said.

"We may not know the true impact for many months, if not more – if not ever," she said.

The impact on SolarWinds was more immediate. US officials ordered anyone running Orion to immediately disconnect it. The company's stock has tumbled more than 23% from $23.50 on Friday - before Reuters broke the news of the breach - to $18.06 on Tuesday.

SolarWinds' security, meanwhile, has come under new scrutiny.

In one previously unreported issue, multiple criminals have offered to sell access to SolarWinds' computers through underground forums, according to two researchers who separately had access to those forums.

One of those offering claimed access over the Exploit forum in 2017 was known as "fxmsp" and is wanted by the FBI "for involvement in several high-profile incidents," said Mark Arena, chief executive of cybercrime intelligence firm Intel471. Arena informed his company's clients, which include US law enforcement agencies.

Security researcher Vinoth Kumar told Reuters that, last year, he alerted the company that anyone could access SolarWinds' update server by using the password "solarwinds123"

"This could have been done by any attacker, easily," Kumar said.

Neither the password nor the stolen access is considered the most likely source of the current intrusion, researchers said.

Others - including Kyle Hanslovan, the cofounder of Maryland-based cybersecurity company Huntress - noticed that, days after SolarWinds realized their software had been compromised, the malicious updates were still available for download.

The firm has long mooted the idea of spin-off of its managed service provider business and on Dec. 9 announced that Thompson would be replaced by Sudhakar Ramakrishna, the former chief executive of Pulse Secure. Three weeks ago, SolarWinds posted a job ad seeking a new vice president for security; the position is still listed as open.

Thompson and Ramakrishna could not be reached for comment.

World+Biz

Hackers / SolarWinds / spy campaign

Comments

While most comments will be posted if they are on-topic and not abusive, moderation decisions are subjective. Published comments are readers’ own views and The Business Standard does not endorse any of the readers’ comments.

Top Stories

  • File Photo. Picture: Mumit M/TBS
    Inflation forcing people to edge
  • Photo: Noor-A-Alam
    How fixed rate regime makes Bangladesh Bank’s monetary tools ineffective
  • A labourer carries a sack filled with sugar to load it onto a supply truck at a wholesale market in Kolkata, India, November 14, 2018. REUTERS/Rupak De Chowdhuri
    India restricts sugar exports at 10 million tonnes

MOST VIEWED

  • Samsung Electronics Vice Chairman, Jay Y Lee, leaves the Seoul high court in Seoul, South Korea, October 25, 2019. REUTERS/Kim Hong-Ji
    Samsung boss Lee hosts Biden, Yoon in tour of S Korea chip plant
  • A smartphone with the Huawei and 5G network logo is seen on a PC motherboard in this illustration picture taken 29 January 2020. Photo:REUTERS
    Canada to ban Huawei/ZTE 5G equipment, joining Five Eyes allies
  • Software programmers walk out of the International Technology Park Ltd (ITPL) building which houses nearly 50 technology firms in Bangalore. Photo: Reuters
    JPMorgan downgrades India's IT sector as Covid boom fades
  • Photo: PR
    Grameenphone launches 'GP Academy' in partnership with Telenor and Cisco
  • FILE PHOTO: An image of Elon Musk is seen on a smartphone placed on printed Twitter logos in this picture illustration taken April 28, 2022. REUTERS/Dado Ruvic/Illustration
    Elon Musk can't easily give Twitter the boot over bots
  • A China-made Tesla Model 3 electric vehicle is seen ahead of the Guangzhou auto show in Guangzhou, Guangdong province, China November 21, 2019. Photo :Reuters
    China in talks with automakers on EV subsidy extension -sources

Related News

  • Espionage-focused hacker group, Bitter APT, allegedly targets RAB
  • Hackers interrupt briefing by lawyers for those killed in airliner downed by Iran
  • Hackers compromise FBI email system, send thousands of messages
  • Hackers of SolarWinds stole data on US sanctions policy, intelligence probes
  • Wide-ranging SolarWinds probe sparks fear in Corporate America

Features

Psycure has received various awards for their extraordinary contributions to promoting Sustainable Development Goals. Photo: Courtesy

Psycure: Meet the organisation serving the underserved university students (and beyond) with mental healthcare 

2h | Panorama
Underlying problems such as school dropouts need to be addressed first before taking a legal route to stop child labour. Photo: Reuters

‘Child labour in a country like Bangladesh is primarily a development issue, not so much of enforcement’

3h | Panorama
The balcony railings of the Boro Sardar Bari in Sonargaon. Made of cast iron, these railings feature vertical posts with intricate designs on top. Photo: Noor-A-Alam

The evolution of railing and grille designs

1d | Habitat
A Russian army service member fires a howitzer during drills at the Kuzminsky range in the southern Rostov region, Russia January 26, 2022. REUTERS/Sergey Pivovarov/File Photo

3 months of Ukraine war : Miscalculations, resistance and redirected focus

1d | Analysis

More Videos from TBS

The alarming effects of the global food crisis

The alarming effects of the global food crisis

53m | Videos
Mangoes from Satkhira going to Iraq

Mangoes from Satkhira going to Iraq

2h | Videos
The dream of building home on moon

The dream of building home on moon

2h | Videos
When is the right time to invest?

When is the right time to invest?

3h | Videos

Most Read

1
Tk100 for bike, Tk2,400 for bus to cross Padma Bridge
Bangladesh

Tk100 for bike, Tk2,400 for bus to cross Padma Bridge

2
A packet of US five-dollar bills is inspected at the Bureau of Engraving and Printing in Washington March 26, 2015. REUTERS/Gary Cameron
Banking

Dollar hits Tk100 mark in open market

3
Bangladesh at risk of losing ownership of Banglar Samriddhi
Bangladesh

Bangladesh at risk of losing ownership of Banglar Samriddhi

4
BSEC launches probe against Abul Khayer Hero and allies
Stocks

BSEC launches probe against Abul Khayer Hero and allies

5
The reception is a volumetric box-shaped room that has two glass walls on both the front and back ends and the other two walls are adorned with interior plants, wood and aluminium screens. Photo: Noor-A-Alam
Habitat

The United House: Living and working inside nature

6
Illustration: TBS
Banking

Let taka slide

The Business Standard
Top
  • Home
  • Entertainment
  • Sports
  • About Us
  • Bangladesh
  • International
  • Privacy Policy
  • Comment Policy
  • Contact Us
  • Economy
  • Sitemap
  • RSS

Contact Us

The Business Standard

Main Office -4/A, Eskaton Garden, Dhaka- 1000

Phone: +8801847 416158 - 59

Send Opinion articles to - oped.tbs@gmail.com

For advertisement- sales@tbsnews.net

Copyright © 2022 THE BUSINESS STANDARD All rights reserved. Technical Partner: RSI Lab