Security News > 2021 > May > SolarWinds Hackers Impersonate U.S. Government Agency in New Attacks

The Russia-linked threat group believed to be behind the SolarWinds attack has been observed launching a new campaign this week.
The attacks have targeted the United States and other countries, and involve a legitimate mass mailing service and impersonation of a government agency.
The latest attacks were analyzed by Microsoft, which tracks the threat actor as Nobelium, and by incident response firm Volexity, which has found some links to APT29, a notorious cyberspy group previously linked to Russia.
For this attack, Nobelium managed to compromise the Constant Contact account of the United States Agency for International Development, which is responsible for civilian foreign aid and development assistance.
Constant Contact is an email marketing service, and by compromising the Constant Contact account of USAID the attackers were able to send out legitimate-looking emails containing malicious links.
Microsoft said its security solutions blocked many of the attacks aimed at its customers and the tech giant has started notifying targets.
News URL
Related news
- Chinese Hackers Exploit MAVInject.exe to Evade Detection in Targeted Cyber Attacks (source)
- Bybit Hack Traced to Safe{Wallet} Supply Chain Attack Exploited by North Korean Hackers (source)
- Hackers Exploit Paragon Partition Manager Driver Vulnerability in Ransomware Attacks (source)
- Hackers Exploit AWS Misconfigurations to Launch Phishing Attacks via SES and WorkMail (source)
- New ‘Rules File Backdoor’ Attack Lets Hackers Inject Malicious Code via AI Code Editors (source)
- TechRepublic EXCLUSIVE: New Ransomware Attacks are Getting More Personal as Hackers ‘Apply Psychological Pressure” (source)
- Hackers Repurpose RansomHub's EDRKillShifter in Medusa, BianLian, and Play Attacks (source)
- Chinese FamousSparrow hackers deploy upgraded malware in attacks (source)
- North Korean hackers adopt ClickFix attacks to target crypto firms (source)
- Russian hackers attack Western military mission using malicious drive (source)