Microsoft Corp. (NASDAQ:MSFT) is warning that the hacker group behind the SolarWinds cyberattack last year is now targeting government agencies, think tanks, consultants, and non-governmental organizations (NGOs).
Called "Nobelium" and originating from Russia, the hacker group is the same once behind the crippling attacks on SolarWinds customers in 2020, according to Microsoft.
The comments come weeks after a May 7 ransomware attack on the Colonial Pipeline shut the United States' largest fuel pipeline network for several days, disrupting the country's energy supply.
While organizations in the U.S. received the largest share of attacks, targeted victims came from at least 24 countries in the latest attack, Microsoft said. At least a quarter of the targeted organizations are involved in international development, humanitarian issues and human rights work.
Nobelium launched this week's attacks by breaking into an email marketing account used by the United States Agency for International Development (USAID) and from there launched phishing attacks on many organizations, said Microsoft.
The hack of information technology company SolarWinds (NYSE:SWI), which was identified last December, gave access to thousands of companies and government offices that used its products. Microsoft President Brad Smith described the SolarWinds attack as "the largest and most sophisticated attack the world has ever seen."
This month, Russia's spy chief denied responsibility for the SolarWinds cyberattack but said he was "flattered" by the accusations from the U.S. and Britain that Russian foreign intelligence was behind such a sophisticated hack.
The latest attacks disclosed by Microsoft appear to be a continuation of multiple efforts to target American government agencies involved in foreign policy as part of intelligence gathering efforts by the Russians.
Related Stories