In an advisory released on October 24, Microsoft announced ongoing campaigns it has attributed to the Nobelium state-sponsored threat group. IBM X-Force tracks this group as Hive099. If the name sounds familiar, that’s because it is the same group that targeted SolarWinds in 2020. The U.S. government has identified Nobelium as part of Russia’s foreign intelligence service known as the SVR.

Microsoft warns that the activity they are seeing appears to focus on cloud service resellers, technology providers, and their downstream customers in Europe and the U.S. organizations are urged to take notice and act to mitigate the risk of compromise.

Abusing digital trust relationships

The ongoing wave of attacks is designed to abuse trusted relationships, such as delegated administrative privilege (DAP). Those can enable attackers to move through the channels that underpin provider/customer relationships. With the goal of compromising accounts at the service provider level, activity has persisted through summer of 2021 and does not appear to exploit any specific vulnerabilities. Instead, the attackers are reported to be using a toolkit of malware, password spraying, API abuse, and spear-phishing to obtain stolen credentials and infiltrate networks with privileged access.

These attack tactics are not novel, and organizations can arm themselves better to reduce the chance of compromise by using multi-factor authentication. Further mitigation can come from restricting the use of privileged access by employees and third parties alike. It is also recommended to review DAP and terminate unused access or places where suspicious activity may have been logged.

Remain vigilant

At this time, IBM recommends that organizations with increased risk to Nobelium attacks begin looking into their specific implementations, both in cloud environments and on premises.

IBM is closely monitoring the overall situation and is engaged with clients and the security community. More details can be found in our designated X-Force Exchange collection, which will be updated as this situation evolves.

Assistance is also available to assist 24×7 via IBM Security X-Force’s US hotline 1-888-241-9812 | Global hotline (+001) 312-212-8034.

More from Government

How the FBI Fights Back Against Worldwide Cyberattacks

5 min read - In the worldwide battle against malicious cyberattacks, there is no organization more central to the fight than the Federal Bureau of Investigation (FBI). And recent years have proven that the bureau still has some surprises up its sleeve. In early May, the U.S. Department of Justice announced the conclusion of a U.S. government operation called MEDUSA. The operation disrupted a global peer-to-peer network of computers compromised by malware called Snake. Attributed to a unit of the Russian government Security Service,…

How NIST Cybersecurity Framework 2.0 Tackles Risk Management

4 min read - The NIST Cybersecurity Framework 2.0 (CSF) is moving into its final stages before its 2024 implementation. After the public discussion period to inform decisions for the framework closed in May, it’s time to learn more about what to expect from the changes to the guidelines. The updated CSF is being aligned with the Biden Administration’s National Cybersecurity Strategy, according to Cherilyn Pascoe, senior technology policy advisor with NIST, at the 2023 RSA Conference. This sets up the new CSF to…

Why keep Cybercom and the NSA’s dual-hat arrangement?

4 min read - The dual-hat arrangement, where one person leads both the National Security Agency (NSA) and U.S. Cyber Command (Cybercom), has been in place since Cybercom’s creation in 2010. What was once touted as temporary 13 years ago now seems established. Will the dual-hat arrangement continue? Should it? Experts have discussed the pros and cons of both viewpoints for years. It remains in place for now, but is that likely to change in the future? That remains to be seen, and points…

New Hive0117 phishing campaign imitates conscription summons to deliver DarkWatchman malware

8 min read - IBM X-Force uncovered a new phishing campaign likely conducted by Hive0117 delivering the fileless malware DarkWatchman, directed at individuals associated with major energy, finance, transport, and software security industries based in Russia, Kazakhstan, Latvia, and Estonia. DarkWatchman malware is capable of keylogging, collecting system information, and deploying secondary payloads. Imitating official correspondence from the Russian government in phishing emails aligns with previous Hive0117 campaigns delivering DarkWatchman malware, and shows a possible significant effort to induce a sense of urgency as…