Microsoft said the Russian state-linked actor Nobelium targeted cloud resellers and technology service providers as a route into the global IT supply chain, relying on password spraying, phishing, and credential theft rather than software exploits. The company said it had notified more than 140 resellers and service providers since May 2021 and believed up to 14 were compromised, while between July 1 and October 19 it alerted 609 customers to 22,868 attacks. Microsoft responded by tightening partner-access protections, including stronger MFA requirements, expanded Azure Active Directory security offerings, and new detections across its security tools.
France’s ANSSI/CERT-FR separately reported multiple Nobelium-linked phishing campaigns beginning in February 2021 that compromised email accounts at French organizations and then used those accounts to send weaponized phishing emails to foreign institutions. French public-sector entities also received spoofed messages masquerading as compromised foreign organizations, and ANSSI said the activity shared tactics, techniques, and procedures with the SolarWinds intrusion set. The combined reporting shows a sustained campaign to abuse trusted service-provider and email relationships to reach downstream victims across national and organizational boundaries.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
CERT-FR issued report CERTFR-2021-CTI-011 detailing phishing campaigns attributed to the Nobelium intrusion set, including associated TTPs, infrastructure, recommendations, and indicators of compromise. ANSSI said the activity showed overlaps with the 2020 SolarWinds supply-chain attack.
Microsoft publicly reported that it had notified more than 140 resellers and technology service providers targeted by Nobelium since May 2021 and believed up to 14 had been compromised. It assessed that the Russian state-linked actor was seeking long-term access through trusted technology partners into downstream customer environments.
Between July 1 and October 19, 2021, Microsoft said it notified 609 customers that they had been attacked 22,868 times by Nobelium. Microsoft described this as part of a broader summer 2021 wave of activity, with a low-single-digit success rate.
Microsoft said that on October 15 it launched a program offering two years of Azure Active Directory Premium for free to strengthen partner security controls amid the Nobelium activity.
Microsoft said it began observing a 2021 Nobelium campaign in May 2021 that targeted cloud resellers and technology service providers as a route into customer environments. The company said the actor used password spraying and phishing rather than exploiting software vulnerabilities.
ANSSI reported that phishing campaigns attributed to the Nobelium intrusion set had targeted French entities since February 2021. The campaigns compromised email accounts at French organizations and used them to send weaponized emails to foreign institutions, while French public organizations also received spoofed emails.
Microsoft said that in September 2020 it rolled out multi-factor authentication for access to Partner Center and for use of delegated administrative privilege to manage customer environments, and updated reseller contracts to expand its rights to address reseller security incidents.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
microsoft.com
Open sourcecert.ssi.gouv.fr
Open sourceblogs.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.