News: 1607971206

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Backdoored SolarWinds software, linked to US govt hacks, in wide use throughout the British public sector

(2020/12/14)


Concern is gathering over the effects of the backdoor inserted into SolarWinds' network monitoring software on Britain's public sector – as tight-lipped government departments refuse to say whether UK institutions were accessed by Russian spies.

As [1]reported in the small hours of this morning by The Register , it appears the downloads page for SolarWinds' Orion Windows monitoring platform was altered by Kremlin hackers – known as APT29, aka Cozy Bear – so that victims fetched and installed a tampered-with version that included a remote-control backdoor.

This malicious code was [2]detailed by FireEye, which itself said it was earlier [3]hacked by state-level miscreants. Said victims of the Orion job are said to include the Treasury and the Dept of Commerce at the US government. It's not clear at this stage whether FireEye was also hacked via a dodgy Orion install.

Research by The Register has shown that SolarWinds' Orion is used widely across the British public sector, ranging from the Home Office and Ministry of Defence through NHS hospitals and trusts, right down to local city councils.

A job advert for the MoD's Corsham tech bunker [4]lists SolarWinds as one of the tools used by a third-line software support engineer; similarly, a network design engineer [5]job with the MoD's Defence Equipment and Support agency posted in May also listed SolarWinds proficiency as a "nice-to-have" skill.

[6]

A list of SolarWinds' UK customers taken from a marketing presentation issued by the company. Click to enlarge.

SolarWinds' products are in regular use in the Royal Navy and Royal Air Force, with the agency also counting GCHQ, the Cabinet Office, and the Ministry of Justice among its customers. Most concerningly, [7]a company brochure [PDF] also stated that the MoD's Defence Equipment and Support agency was a SolarWinds customer. DE&S is the agency that maintains Britain's high-tech fighter jets, submarines, and warships.

Local governments also facing possible storm

Down at local government level, the three London boroughs of Brent, Lewisham, and Southwark all use SolarWinds Orion as part of a joint backend IT venture. Meeting [8]minutes [PDF] from July revealed: "The service has also standardised on the Orion SolarWinds monitoring product, initially for the network infrastructure, but this will be expanded to cover other key components such as server compute and storage."

Other councils around the country also use the product, with the National Cyber Security Centre (NCSC) advising orgs using it to "have these instances installed behind firewalls, disabling internet access for the instances, and limiting the ports and connections to only what are critically necessary".

Yet government departments fobbed off El Reg 's questions about the hack, referring us to the NCSC's public statement, which merely said it was "working closely with FireEye and international partners on this incident."

Microsoft has published a [9]detailed technical blog about the SolarWinds compromise, speculating that the Russians may have "compromised internal build or distribution systems of SolarWinds, embedding backdoor code into a legitimate SolarWinds library with the file name SolarWinds.Orion.Core.BusinessLayer.dll". SolarWinds' customers are being urgently advised by the firm to upgrade to Orion Platform version 2020.2.1 HF 1 "as soon as possible to ensure the security of your environment."

And speaking of Microsoft, SolarWinds, in a filing

[10]PDF

to America's securities watchdog, said its Office 365 email and productivity suite account was hacked, which we're guessing could have led to the quiet tampering of its downloads:

SolarWinds uses Microsoft Office 365 for its email and office productivity tools. SolarWinds was made aware of an attack vector that was used to compromise the Company’s emails and may have provided access to other data contained in the Company’s office productivity tools. SolarWinds, in collaboration with Microsoft, has taken remediation steps to address the compromise and is investigating whether further remediation steps are required, over what period of time this compromise existed and whether this compromise is associated with the attack on its Orion software build system. SolarWinds also is investigating in collaboration with Microsoft as to whether any customer, personnel or other data was exfiltrated as a result of this compromise but has uncovered no evidence at this time of any such exfiltration.

SolarWinds also said of its more than 300,000 customers, up to 18,000 of them installed the dodgy Orion update – said to include America's Homeland Security among other US government bodies.

The normally talkative cybersecurity sector has been practically silent about the FireEye hack, which sources suggested to The Register was because smaller firms are scared of being seen to criticise one of the industry's largest players. Meanwhile, the NCSC's refusal to answer any questions about the breach suggests its impact may well be larger than officials want to admit.

Nuke it from orbit

The US government's Cybersecurity and Infrastructure Security Agency (CISA) issued an [11]emergency directive on Sunday evening calling for an immediate IT lockdown by government agencies: specifically, pull the plug on anything running Orion.

"Affected agencies shall immediately disconnect or power down SolarWinds Orion products, versions 2019.4 through 2020.2.1 HF1, from their network," the directive stated.

"Until such time as CISA directs affected entities to rebuild the Windows operating system and reinstall the SolarWinds software package, agencies are prohibited from (re)joining the Windows host OS to the enterprise domain."

In addition, Uncle Sam's IT admins are told to block all incoming and outgoing traffic from machines "where any version of SolarWinds Orion software has been installed," conduct forensic analysis of new user or service accounts, and to analyze network logs to look for suspicious behavior.

CISA also warned that even if servers look clear, administrators should "treat all hosts monitored by the SolarWinds Orion monitoring software as compromised by threat actors and assume that further persistence mechanisms have been deployed." ®

Get our [12]Tech Resources



[1] https://www.theregister.com/2020/12/14/solarwinds_fireeye_cozybear/

[2] https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html

[3] https://www.theregister.com/2020/12/09/fireeye_tools_hacked/

[4] https://contracts.contractspy.co.uk/job/50136/level-3-wintel-engineer-dv-ceared-at-ministry-of-defence-corsham-12-months-contract-rate/

[5] https://www.digitalmarketplace.service.gov.uk/digital-outcomes-and-specialists/opportunities/12341

[6] https://regmedia.co.uk/2020/12/14/solarwindscustomers.jpg

[7] https://www.solarwinds.com/-/media/solarwinds/swdcv2/landing-pages/uk-nhs/sw-federal-nhs-one-pager-0818.ashx?la=en&rev=b40ec51a2a404f93b47176676b10823f&hash=2A947F10D8478271AC64610E435DB96BE822CFDA

[8] http://moderngov.southwark.gov.uk/documents/s89784/Supplementary%20Agenda%20Pack%20-%20Joint%20Boroughs%20IT%20Committee%208%20July%202020.pdf

[9] https://msrc-blog.microsoft.com/2020/12/13/customer-guidance-on-recent-nation-state-cyber-attacks/

[10] https://regmedia.co.uk/2020/12/14/sec_solarwinds.pdf

[11] https://cyber.dhs.gov/ed/21-01/

[12] https://whitepapers.theregister.com/

Hello Ms Goose, Meet Mr Gander

amanfromMars 1

The hack was carried out by a hacking crew thought to be APT29, aka Cozy Bear, a crew of miscreants linked to Russia's Foreign Intelligence Service, though no firm evidence has yet been put forward publicly.

Here's pretty current news of wannabe UK miscreants ...... [1]https://www.theguardian.com/technology/2020/nov/19/uk-unveils-national-cyber-force-of-hackers-to-target-foes-digitally ..... which by all accounts is something to be lauded and applauded.

It's a funny old world and that's for sure. Not many folk laughing though.

[1] https://www.theguardian.com/technology/2020/nov/19/uk-unveils-national-cyber-force-of-hackers-to-target-foes-digitally

An eye for an eye, and soon the whole world will be blind

el kabong

But since, apparently, Britain has already committed to retaliation then they better do it properly.

World beating retaliation is in order, anything short of that will not do.

Yup time to fire off

Nursing A Semi

An order for some more natural gas, if you don't mind, thank you very much.

No Cause for Concern in the UK

Anonymous Coward

On the Basis that the infected updates were for 2019/2020 releases of SolarWinds, i don't expect many UK Public Sector IT teams will be anything like that current. We'll be lucky if they have Win 10 yet.

I mean, the BBC has PCs in the back of shot during the news running Win 7 - what are the chances their back end will be up to date?

Re: No Cause for Concern in the UK

HAL-9000

I heard the NHS runs on XP ;)

Re: No Cause for Concern in the UK

Giles C

I saw this week that they are planning on updating the backdrops, something about they have used the same ones for years. Doesn’t mean they have updated the computers though...

Thanks Vlad

HAL-9000

Another poop storm brewing, the bit where we Brit's aren't even allowed to know WTF has been going on is truly reassuring. I suppose there's a slim chance that Alexander of Uxbridge and South Ruislip will find his mucky web habits posted on Wikileaks imminently, or probably more interesting to know... what the hell our government and security services are up to. Is there a runner up prize for predicting the usual suspects will maintain that software and hardware back doors are essential for maintaining national security, like giving all our secrets away to Russian state backed hackers

Doctor Syntax

And have they learned anything from this about the advisability of back doors in software?

Anonymous Coward

I wonder how came up with this question...

If he had only learnt a little less, how infinitely better he might have
taught much more!