The Russian hackers Nobelium, responsible for one of the largest hacking attacks of the past year against the U.S. government and dozens of private companies, including SolarWinds Corp., have stepped up their attacks in recent months, breaking into technology companies in an attempt to steal sensitive information. Microsoft has shared the latest activity it has observed from the Russian Nobelium group. In the article below, you will see all the details the company has provided about this group.

See also: Ferrara Candy: Hit by ransomware just before Halloween
Nobelium is attempting to repeat the approach it has used in previous attacks by targeting organizations that are integral to the global IT supply chain. This time, it is attacking a different part of the supply chain: resellers and other technology service providers that customize, deploy, and manage cloud services and other technologies on behalf of their customers. Microsoft says, “We believe Nobelium ultimately hopes to regain any direct access that resellers may have to their customers’ IT systems and more easily impersonate an organization’s trusted technology partner to gain access to their downstream customers. We began monitoring this latest campaign in May 2021 and have notified affected partners and customers, while also developing new technical assistance and guidance for the reseller community.”
Microsoft continues by saying: “Since May, we have notified more than 140 resellers and technology service providers that have been targeted by Nobelium. We are continuing our investigation, but to date we believe that up to 14 of these resellers and service providers have been compromised. Fortunately, we discovered this campaign in its early stages and are sharing these developments to help cloud resellers, technology providers, and their customers take timely action to ensure that Nobelium does not continue to achieve its goals.”
See also: Italian celebrities' data exposed in ransomware attack on SIAE
These attacks were part of a larger wave of hacker activity. In fact, between July 1 and October 19 of this year, 609 customers were notified that they had been attacked by Nobelium.

This recent activity is another indicator that Russia is trying to gain long-term, systematic access to various parts of information systems and create a mechanism to monitor – now or in the future – targets of interest to the Russian government. While we share details about Nobelium’s latest activity here, the Microsoft Digital Defense Report, published earlier this month, highlights ongoing attacks by other cybercriminals. In light of these attacks, Microsoft notifies its customers when they are targeted or compromised by these hackers.
The attacks detected in the recent campaign against resellers and service providers did not attempt to exploit any flaw or vulnerability in the software, but instead used well-known techniques, such as password spray and phishing, to steal legitimate credentials and gain privileged access.
Microsoft continues by saying: “We are also coordinating with others in the security community to improve our understanding of and protections against Nobelium activity, and we are working closely with government agencies in the US and Europe. While we clearly know that nation-states, including Russia, will not stop attacks like these overnight, we believe that steps like the US Cybersecurity Executive Order and the greater coordination and information sharing we have seen between industry and government over the past two years have put us all in a much better position to defend against them.”
See also: Evil Corp: Demands $40 million in Macaw ransomware attacks
Microsoft says: “We have long maintained and developed the security requirements and policies we implement with service providers who sell or support Microsoft technology. For example, in September 2020, we updated our reseller agreements to expand Microsoft’s capabilities and rights to respond to reseller security incidents and to require resellers to implement specific security protections for their environment, such as restricting access to the Partner Portal and requiring resellers to enable multi-factor authentication (MFA) for access to our cloud portals and underlying services, and we will take necessary and appropriate steps to enforce these security commitments. We continue to evaluate and identify new opportunities for greater security across our partner ecosystem, recognizing the need for continuous improvement. As a result of what we have learned over the past few months, we are working to implement improvements that will help better secure and protect the ecosystem, especially for technology professionals.” partners in our supply chain.”

Specifically:
- As noted above, in September 2020, Microsoft rolled out MFA for accessing Partner Center and for using delegated administrative privilege (DAP) to manage a customer environment
- On October 15, a program was launched to provide a free two-year Azure Active Directory Premium plan that provides expanded access to additional premium features to strengthen security controls
- Microsoft threat protection tools and security features, such as Microsoft Cloud App Security (MCAS), M365 Defender, Azure Defender, and Azure Sentinel, have added detections to help organizations detect and respond to these attacks
- New and more granular features are currently being piloted for organizations that want to provide privileged access to resellers
- Improved monitoring is implemented to enable partners and customers to manage and control their delegated privileged accounts and remove unnecessary authority
- Unused privileged accounts are checked and unnecessary privileges and accesses are removed
The company is also publishing technical guidance that can help organizations protect themselves from the most recent Nobelium activity that has been observed, as hackers have improved their techniques.
Information source: blogs.microsoft.com
