Microsoft stated that Nobelium, the Russian-backed threat group responsible for the SolarWinds hack, has attacked 140 managed service providers (MSPs) and cloud service providers since May. Tom Burt, Corporate Vice President at Microsoft, stated that 14 of the 140 MSPs were successfully breached. In addition, more than 600 Microsoft customers were attacked, although with a low success rate. The Russian hackers use a diverse set of tools to carry out these attacks including tactics ranging from malware, password sprays, and token theft to API abuse and spear phishing. Nobelium is the hacking division of the Russian Foreign Intelligence Services and is also tracked as APT29, Cozy Bear, and The Dukes. The group continues to carryout aggressive espionage campaigns to gain long term access to systems and steal information.
When evaluating a Managed Detection & Response (MDR) service there are 5 critical components that