SolarWinds Hackers Linked to Known Russian Spying Tools, Kaspersky Investigators Say

The findings are the first publicly-available evidence to support assertions by the US that Russia orchestrated the hack.

Advertisement
By Reuters | Updated: 12 January 2021 11:01 IST
Highlights
  • Moscow has repeatedly denied the allegations
  • The findings are first publicly-available evidence to support assertions
  • Security teams are working to determine full scope of SolarWinds hack

Security teams in the US and other countries are still working to determine full scope of SolarWinds hack

The group behind a global cyber-espionage campaign discovered last month deployed malicious computer code with links to spying tools previously used by suspected Russian hackers, researchers said on Monday.

Investigators at Moscow-based cyber-security firm Kaspersky said the "backdoor" used to compromise up to 18,000 customers of US software maker SolarWinds closely resembled malware tied to a hacking group known as "Turla," which Estonian authorities have said operates on behalf of Russia's FSB security service.

The findings are the first publicly-available evidence to support assertions by the United States that Russia orchestrated the hack, which compromised a raft of sensitive federal agencies and is among the most ambitious cyber operations ever disclosed.

Advertisement

Moscow has repeatedly denied the allegations. The FSB did not respond to a request for comment.

Advertisement

Costin Raiu, head of global research and analysis at Kaspersky, said there were three distinct similarities between the SolarWinds backdoor and a hacking tool called "Kazuar" which is used by Turla.

The similarities included the way both pieces of malware attempted to obscure their functions from security analysts, how the hackers identified their victims, and the formula used to calculate periods when the viruses lay dormant in an effort to avoid detection.

Advertisement

"One such finding could be dismissed," Raiu said. "Two things definitely make me raise an eyebrow. Three is more than a coincidence."

Confidently attributing cyber-attacks is extremely difficult and strewn with possible pitfalls. When Russian hackers disrupted the Winter Olympics opening ceremony in 2018, for example, they deliberately imitated a North Korean group to try and deflect the blame.

Advertisement

Raiu said the digital clues uncovered by his team did not directly implicate Turla in the SolarWinds compromise, but did show there was a yet-to-be determined connection between the two hacking tools.

It's possible they were deployed by the same group, he said, but also that Kazuar inspired the SolarWinds hackers, both tools were purchased from the same spyware developer, or even that the attackers planted "false flags" to mislead investigators.

Security teams in the United States and other countries are still working to determine the full scope of the SolarWinds hack. Investigators have said it could take months to understand the extent of the compromise and even longer to evict the hackers from victim networks.

US intelligence agencies have said the hackers were "likely Russian in origin" and targeted a small number of high-profile victims as part of an intelligence-gathering operation.

© Thomson Reuters 2020


What will be the most exciting tech launch of 2021? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: SolarWinds, Kaspersky
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15R Confirmed to Launch Soon: Know Expected Features
  2. OTT Releases of the Week: Dude, Nishaanchi, Jolly LLB 3, and More
  3. Samsung Silently Introduces Galaxy Book 5 Edge 5G With These Features
  4. Oppo Reno 15 Series to Launch in These Storage Variants, Colourways
  5. Honor 500 Pro Specifications Surface Ahead of Launch in China
  6. Oppo Find X9 Series Could Launch in India at This Price
  7. Pixel Call Recording Finally Rolling Out to Older Models After Long Delay
  8. Vivo X300 Series Specs Confirmed, India-Exclusive Red Colour Teased
  1. BSNL Announces Silver Jubilee Prepaid Recharge Plan With 2.5GB of Daily Data, Unlimited Calls for 30 Days
  2. Blue Origin Joins SpaceX in Orbital Booster Reuse Era With New Glenn’s Successful Launch and Landing
  3. AI-Assisted Study Finds No Evidence of Liquid Water in Mars’ Seasonal Dark Streaks
  4. Bison OTT Release Date Reportedly Revealed Online: When and Where to Watch it Online?
  5. Kathleen Madigan: The Family Thread OTT Release Date: When and Where to Watch it Online?
  6. All Her Fault Now Streaming on OTT: Know Where to Watch it Online
  7. Fallout Season 2 OTT Release Date: When and Where to Watch it Online?
  8. Google Expands Native Call Recording to Older Pixel Phones With Latest Update
  9. Google DeepMind Introduces SIMA 2, a Gemini-Powered AI Agent That Can Play Video Games
  10. Vivo S50 Series Tipped to Launch Next Month With a Snapdragon Chip
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.