Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • News
  • How-to
  • Feature stories
  • Deals
  • Microsoft / office 365
  • Reviews
Menu
  • Home
  • About
  • Contact
  • News
  • How-to
  • Feature stories
  • Deals
  • Microsoft / office 365
  • Reviews
  1. Home
  2. News
  3. Microsoft identifies a second SolarWinds-like attack from Russian based hackers – onmsft.com

Microsoft identifies a second SolarWinds-like attack from Russian based hackers – onmsft.com

Kareem Anderson Kareem Anderson
October 25, 2021
2 min read

Companies are still reeling from the sophisticated large scale 2020 SolarWinds attack which affected up to 320,000 businesses in over 190 countries, and it appears there is a second attempt under away.

Microsoft has managed to identify a second nascent attack on the horizon that is deploying a similar Trojan-horse technique to gain direct access to cloud services used by global IT supply chains.

In a blog post authored by Microsoft’s corporate vice president of Customer Security & Trust, Tom Burt names Russian nation-state actor Nobelium as the same perpetrators of both the original SolarWinds attack and this new copycat attempt.

Nobelium has been attempting to replicate the approach it has used in past attacks by targeting organizations integral to the global IT supply chain. This time, it is attacking a different part of the supply chain: resellers and other technology service providers that customize, deploy and manage cloud services and other technologies on behalf of their customers. We believe Nobelium ultimately hopes to piggyback on any direct access that resellers may have to their customers’ IT systems and more easily impersonate an organization’s trusted technology partner to gain access to their downstream customers.

Microsoft has been keeping an eye on Nobelium since May of this year and alerting its vulnerable partners and customers which has been more than 140 resellers and service technology providers.

Sadly, Microsoft believes of the 140, at least 14 have been seriously compromised by the new attack. On the plus side, Microsoft also believes it’s caught Nobelium in the preliminary stages despite an increase in activity during the summer.

Similar to SolarWinds, Nobelium is looking to weaponize a long-term strategy of surveillance on potential Russian targets in the future, according to Microsoft.

The attacks we’ve observed in the recent campaign against resellers and service providers have not attempted to exploit any flaw or vulnerability in software but rather used well-known techniques, like password spray and phishing, to steal legitimate credentials and gain privileged access. We have learned enough about these new attacks, which began as early as May this year, that we can now provide actionable information which can be used to defend against this new approach.

Microsoft notes Nobelium isn’t the only nation-state attempting to gain illegal access to resellers IT supply chains, but it is among the most aggressive at the moment.

Microsoft is collaborating with authorities and the security community in US and European government agencies to coordinate and execute counter measures.

Share This Post:

Share this article:
Tags:
IT Supply Chain Microsoft Nobelium Russia SolarWinds
Previous Article Xbox consoles are getting a built-in Twitch live streaming experience Next Article Xbox releases official Age of Empires IV Wolol-o’s cereal with bonus free CD – onmsft.com

Related Articles

Chrome tests Google Drive file uploads in the AI Mode compose box

April 14, 2026
Gemini image creation using right click desktop Chrome

Chrome lets you remake images with Gemini on desktop using just a right-click

April 13, 2026
Samsung Display crosses 5 million QD-OLED monitor shipments as demand grows fast, with new panels and strong premium market expansion worldwide.

Samsung Display Ships 5 Million QD-OLED Monitor Panels in Four Years

April 9, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Chrome tests Google Drive file uploads in the AI Mode compose box
  • Chrome lets you remake images with Gemini on desktop using just a right-click
  • Samsung Display Ships 5 Million QD-OLED Monitor Panels in Four Years
  • Intel Arc Pro B70 Teardown Reveals Blower Cooler and Early Board Design Details
  • Users Modify RTX 5090 Lightning Z Hardware to Unlock MSI’s Restricted 2500W BIOS

Recent Comments

  1. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  2. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Chrome tests Google Drive file uploads in the AI Mode compose box
  • Chrome lets you remake images with Gemini on desktop using just a right-click
  • Samsung Display Ships 5 Million QD-OLED Monitor Panels in Four Years
  • Intel Arc Pro B70 Teardown Reveals Blower Cooler and Early Board Design Details
  • Users Modify RTX 5090 Lightning Z Hardware to Unlock MSI’s Restricted 2500W BIOS

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy