Malwarebytes 'remains safe to use' following attack from SolarWinds threat actor

Malwarebytes Labs
Malwarebytes Labs (Image credit: Malwarebytes)

What you need to know

  • Malwarebytes was attacked by the same threat actor behind the SolarWinds attack.
  • The company does not use SolarWinds but was attacked by the same threat actor that was behind the SolarWinds attack.
  • The attack abused applications with privileged access to Microsoft Office 365.

Malwarebytes explains that the attacker "only gained access to a limited subset of internal company emails" and that it "found no evidence of unauthorized access or compromise in any of [its] internal on-premises and production environments."

The Microsoft Security Response Center notified information about the attack on December 15. Malwarebytes was informed of suspicious activity that was consistent with methods used in the SolarWinds attack.

After being informed of the attack, Malwarebytes activated its incident response group and work with Microsoft's Detection and Response Team to investigate. According to its investigation, the attack leveraged a dormant email protection product within the Malwarebytes Office 365 tenant.

"Our software remains safe to use," says Malwarebytes co-founder and CEO Marcin Kleczynski in the post detailing the attack. Kleczynski explains that Malwarebytes looked at its source code, build and delivery processes, and reverse engineered its own software to make sure that it's still safe to use. The company's systems "showed no evidence of unauthorized access or compromise in any on-premises and production environments," according to Kleczynski.

The threat actors behind the SolarWinds attacks have gone after several large tech companies, including Microsoft. The U.S. government accuse the Russian government of orchestrating the SolarWinds attack (via ZDNet).

Sean Endicott
News Writer and apps editor

Sean Endicott is a news writer and apps editor for Windows Central with 11+ years of experience. A Nottingham Trent journalism graduate, Sean has covered the industry’s arc from the Lumia era to the launch of Windows 11 and generative AI. Having started at Thrifter, he uses his expertise in price tracking to help readers find genuine hardware value.

Beyond tech news, Sean is a UK sports media pioneer. In 2017, he became one of the first to stream via smartphone and is an expert in AP Capture systems. A tech-forward coach, he was named 2024 BAFA Youth Coach of the Year. He is focused on using technology—from AI to Clipchamp—to gain a practical edge.