SolarWinds Hackers Broke Into US Cable Firm and Arizona County, Web Records Show

The hack is one of the biggest-ever uncovered and has sent security teams around the world scrambling to contain the damage.

Advertisement
By Reuters | Updated: 21 December 2020 12:14 IST
Highlights
  • Victims were identified by running a coding script released by Kaspersky
  • The Web record known as CNAME includes unique identifier for each victim
  • SolarWinds disclosed its unwitting role at the centre of the global hack

The hack hijacked software made by SolarWinds to compromise a raft of US government agencies

Suspected Russian hackers accessed the systems of a US Internet provider and a county government in Arizona as part of a sprawling cyber-espionage campaign disclosed this week, according to an analysis of publicly-available Web records.

The hack, which hijacked ubiquitous network management software made by SolarWinds to compromise a raft of US government agencies and was first reported by Reuters, is one of the biggest ever uncovered and has sent security teams around the world scrambling to contain the damage.

The intrusions into networks at Cox Communications and the local government in Pima County, Arizona, show that alongside victims including the US departments of Defence, State, and Homeland Security, the hackers also spied on less high-profile organisations.

Advertisement

A spokesman for Cox Communications said the company was working "around the clock" with the help of outside security experts to investigate any consequences of the SolarWinds compromise. "The security of the services we provide is a top priority," he said.

Advertisement

In emailed comments sent to Reuters, Pima County Chief Information Officer Dan Hunt said his team had followed US government advice to immediately take SolarWinds software offline after the hack was discovered. He said investigators had not found any evidence of a further breach.

Reuters identified the victims by running a coding script released on Friday by researchers at Moscow-based cybersecurity firm Kaspersky to decrypt online Web records left behind by the attackers.

Advertisement

The type of Web record, known as a CNAME, includes an encoded unique identifier for each victim and shows which of the thousands of "backdoors" available to them the hackers chose to open, said Kaspersky researcher Igor Kuznetsov.

"Most of the time these backdoors are just sleeping," he said. "But this is when the real hack begins."

Advertisement

The CNAME records relating to Cox Communications and Pima County were included in a list of technical information published by US cybersecurity firm FireEye Inc, which was the first victim to discover and reveal it had been hacked.

John Bambenek, a security researcher and president of Bambenek Consulting, said he had also used the Kaspersky tool to decode the CNAME records published by FireEye and found they connected to Cox Communications and Pima County.

The records show that the backdoors at Cox Communications and Pima County were activated in June and July this year, the peak of the hacking activity so far identified by investigators.

It is not clear what, if any, information was compromised.

SolarWinds, which disclosed its unwitting role at the centre of the global hack on Monday, has said that up to 18,000 users of its Orion software downloaded a compromised update containing malicious code planted by the attackers.

As the fallout continued to roil Washington on Thursday, with a breach confirmed at the US Energy Department, US officials warned that the hackers had used other attack methods and urged organisations not to assume they were protected if they didn't use recent versions of the SolarWinds software.

Microsoft, which was one of the thousands of companies to receive the malicious update, said it had currently notified more than 40 customers whose networks were further infiltrated by the hackers.

Around 30 of those customers were in the United States, it said, with the remaining victims found in Canada, Mexico, Belgium, Spain, Britain, Israel, and the United Arab Emirates. Most worked information technology companies, as well as some think tanks and government organisations.

"It's certain that the number and location of victims will keep growing," Microsoft President Brad Smith said in a blog post.

"The installation of this malware created an opportunity for the attackers to follow up and pick and choose from among these customers the organisations they wanted to further attack, which it appears they did in a narrower and more focused fashion."

© Thomson Reuters 2020


Is MacBook Air M1 the portable beast of a laptop that you always wanted? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo F31 Series Launched With 7,000mAh Battery: Check Price, Features
  2. Nothing Announces Offers on Phones, Wearables During Flipkart Sale
  3. iOS 26 Update for iPhone Releases Today: Everything You Need to Know
  4. These Realme Phones Will Be Discounted During the Flipkart Big Billion Days Sale
  5. Flipkart Big Billion Days Sale: Discounts on Motorola Phones Announced
  6. Vivo Y31 Series With 6,500mAh Battery Launched in India: See Price
  7. Nothing Phone 3 Price Will Drop to Rs 34,999 on Flipkart, But There's a Catch
  8. Realme P3 Lite 5G With 6,000mAh Battery Launched in India at This Price
  9. Apple Might Launch the iPhone 17e and Nine Other New Products by Early 2026
  10. Butterfly-Shaped Hole in the Sun Could Spark Solar Storms Worldwide
  1. Resident Evil Requiem, Resident Evil 7: Biohazard and Resident Evil Village Are Coming to Switch 2 Next Year
  2. iQOO 15 Live Image Hints at Design; Confirmed to Feature 2K Samsung AMOLED Display
  3. Vivo Y31 Pro 5G, Vivo Y31 5G Launched in India With 6,500mAh Battery, 50-Megapixel Camera: Price, Features
  4. [Exclusive] Noise to Launch Flagship Master Series Over-Ear Headphones With Dynamic EQ
  5. Flipkart Big Billion Days Sale 2025: Motorola Edge 60 Pro, Edge 60 Fusion, Moto G96 5G and More to Get Discounts
  6. Snapdragon 8 Elite Gen 5 Confirmed to Launch as Qualcomm's Upcoming Flagship Mobile Chipset
  7. Flipkart Big Billion Days Sale: Nothing Announces Offers on Phone 3a Pro, CMF Phone 2 Pro, Nothing Ear, and More
  8. Bitcoin Steadies Above $116,400 as Ether and Other Altcoins Show Resilience
  9. Oppo F31 Pro+ 5G Launched in India With 7,000mAh Battery Alongside Oppo F31 Pro 5G, F31 5G: Price, Features
  10. Apple Reportedly Plans to Launch iPhone 17e, MacBook Air M5, and More Products by Early 2026
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.