Malicious Software detected on Microsoft´s servers
The intrusion seems to be related to the latest attack on US government servers.

Microsoft Corp (NASDAQ: MSFT) has announced that malicious software linked to a hacking campaign announced by US authorities last week has been found on its systems. This joins a leading tech company on the long list of government agencies that have been attacked. The company uses Orion, widely used network management software from SolarWinds Corp. that was used by Russian attackers to hack critical US authorities. The Redmond, Washington-based company has used its products in an attack, according to sources familiar with the matter. On Thursday, the US National Security Agency issued a "Cybersecurity Advisory" explaining how hackers compromised some of Microsoft Azure's cloud services. The advisory instructed users to secure their systems. A Microsoft spokesman said it was found that the company's systems had not been used to attack others. The spokesperson added that Microsoft, like most SolarWinds customers, has been actively searching for indicators of the actor and they have discovered malicious SolarWinds binaries in their system that they have isolated and removed. A source familiar with the hacking matter said that actors used Microsoft cloud services but avoided the company's corporate infrastructure. Although Microsoft did not respond to the tech, a person familiar with the matter stated that the Department of Homeland Security (DHS) does not see Microsoft as the main route for further infection. According to the DHS and Microsoft, the hackers used several break-in methods that are still under investigation. The US Department of Energy was one of the hacked entities, which stated that hackers had gained access to its network. Politico had previously reported that the National Nuclear Security Administration was also a target of the hacking attack. A Department of Energy spokeswoman said the malware was restricted to the corporate network only and did not compromise US national security, which includes the NNSA. Interestingly, the hackers not only damaged the SolarWinds network management software, but also used other techniques. The hackers monitored emails and other information within the YS departments of State, Defense, Treasury, Commerce and Homeland Security.





