The suspected Russian hackers who used SolarWinds and Microsoft software to break into US federal agencies emerged with information about counter-intelligence investigations, policy on sanctioning Russian individuals, and the country’s response to Covid-19, According to people familiar with the investigation. The intrusions were widely publicized after their discovery late last year, and American authorities blamed Russia’s SVR foreign surveillance arm, which denies any involvement. However, little information regarding the spies’ goals and accomplishments has been released. The Securities and Exchange Commission has launched an investigation into certain publicly listed firms’ refusal to explain their risk. Officials were worried by the campaign’s secrecy and meticulous staging.
The hackers break into SolarWinds’ code production process, which produces commonly used network management software. The gang also used flaws in Microsoft’s procedures for identifying users in Office 365, penetrating certain targets that didn’t use SolarWinds but did use Microsoft products. According to earlier reports, the hackers entered unclassified Department Of justice networks and read communications from the treasury, commerce, and home affairs departments.
A total of nine government entities were hacked. The SolarWinds hackers allegedly took source code from Microsoft and other major companies and digital certificates that convince computers that software is authorized to execute on them. According to one of the persons concerned, the disclosure of counter-intelligence things being pursued against Russia was the worst of losses. Requests for comment to the Justice Department and the White House were not responded to on Wednesday. Microsoft claimed the Russian agents were eventually seeking government data on sanctions and other Russia-related policies, as well as US tactics for capturing foreign agents, in an annual threat-review report issued on Thursday.
CISA and now a consultant for SolarWinds and other firms. “I have a defined set of aims if I’m a threat actor in an environment.” First and foremost, I’d like to gather useful information on government decision-making. “The policy of sanctions makes a lot of sense,” Krebs added. Others involved in the government’s probe went even farther, claiming that they could see the phrases used by the Russians in their searches of US digital information, including “sanctions. “The combined explanations of the attackers’ aims were plausible, according to Chris Krebs, the former chief of the US cyber-defense organization.


