{"id":45054,"date":"2022-01-28T15:00:00","date_gmt":"2022-01-28T15:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/attacks-breaches\/navigating-nobelium-lessons-from-cloud-hopper-notpetya"},"modified":"2022-01-28T15:00:00","modified_gmt":"2022-01-28T15:00:00","slug":"navigating-nobelium-lessons-from-cloud-hopper-notpetya","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\/","title":{"rendered":"Navigating Nobelium: Lessons From Cloud Hopper &amp; NotPetya"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt481ce449947cf4f5\/61eb1b0ba3de30188f4f0b5e\/SecurityLock_vska_Alamyjpg.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>In December 2020, the threat of supply chain attacks started to seem real to a lot of people. That&#8217;s when FireEye\/Mandiant dropped its <a href=\"https:\/\/www.mandiant.com\/resources\/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor\" target=\"_blank\" rel=\"noopener\">bombshell report<\/a> about a major &#8220;global intrusion campaign&#8221; delivered through Trojan-implanted updates of SolarWinds&#8217; popular Orion software. About 18,000 SolarWinds customers downloaded the update, though the attackers then focused on a subset of high-value targets, including major corporations and federal government agencies. <\/p>\n<p>The SolarWinds incident made a strong point about the far-reaching impact of attacks on the supply chain, particularly because the group behind the campaign hasn&#8217;t stopped. Microsoft detailed in October 2021 that the Russia-based advanced persistent threat (APT) group, <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/solarwinds-attacker-targets-cloud-service-providers-in-new-supply-chain-threat\" target=\"_blank\" rel=\"noopener\">which Microsoft calls Nobelium<\/a>, has branched out from the software supply chain to target IT service providers \u2014 including cloud service providers (CSPs) and managed service providers (MSPs) \u2014 exploiting privileged and administrative credentials to gain access to downstream customers.<\/p>\n<p>Although Nobelium&#8217;s activities display a high level of sophistication, its latest campaign isn&#8217;t new. In 2016\u20132017, I was part of a team at PwC charged with incident response for two major campaigns. The first was a years-long campaign by a Chinese nation-state hacking group that targeted MSPs in order to gain access to major organizations worldwide, known as <a href=\"https:\/\/www.pwc.com\/gx\/en\/about\/stories-from-across-the-world\/unmasking-a-global-cyber-espionage-campaign.html\" target=\"_blank\" rel=\"noopener\">Operation Cloud Hopper<\/a>. The second was the <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/notpetya-how-to-prep-and-respond-if-you-re-hit\" target=\"_blank\" rel=\"noopener\">NotPetya global ransomware campaign<\/a>, which was strikingly similar to SolarWinds in that the actors compromised the software update system of the Ukrainian MeDoc accounting software. The lessons from both are extremely valuable for organizations now defending themselves from Nobelium and the inevitable technology <a href=\"https:\/\/www.darkreading.com\/edge-articles\/why-supply-chain-attacks-are-destined-to-escalate\" target=\"_blank\" rel=\"noopener\">supply chain attacks that are to come<\/a>.<\/p>\n<p>I expect we&#8217;ll see frequent reports about the activities of Nobelium and other threat actors that are living off the land across these supply chains. Nearly every organization should assume it is&nbsp;at risk, but there are ways of countering the APT&#8217;s tactics. Here are several approaches that are essential for enterprises to continuously investigate their networks.<\/p>\n<p><strong>Engage in Continuous Risk Assessments of Third-Party Providers <\/strong><br \/>You should conduct detailed third-party risk assessments that cover not just technical security controls but governance, risk, and compliance. Continuous monitoring, logging, and review of activities between your organization and third parties can be measured against a pre-established baseline of normal activity to help detect anomalies. Having the right checks and balances in place can help mitigate threats coming via providers.<\/p>\n<p><strong>Thoroughly Understand Attack Vectors Across the Supply Chain<\/strong><br \/>Service providers have joined hardware and software as prime targets for attackers. A comprehensive approach to security must include an understanding of the threat landscape, as well as threat groups and their tactics, such as using compromised credentials to exploit unpatched software. A complete view of potential threats \u2014 including those to system architecture, access, and authentication controls \u2014 must be compared not only against the state of your critical systems but also the security postures of partners.<\/p>\n<p><strong>Look Both Inward and Outward<\/strong><br \/>It&#8217;s important to monitor internally as well as externally to protect against these threats. It&#8217;s not unusual for someone with admin credentials to log in to a server and then log in to other servers from there. But that initial access often isn&#8217;t tracked, which can allow an attacker to enter and proceed unnoticed. An organization can put protections around internal access. Also, most organizations don&#8217;t know what their third-party partners have access to. Identity and access management (IAM) should include knowing what privileges third-party partners have and tracking their movements so that unusual behavior triggers an alarm.<\/p>\n<p><strong>Execute on the Principle of Least Privilege<\/strong><br \/>Over-permissioning is a common problem throughout cloud infrastructures. When developers, for example, ask for permission to access server, it&#8217;s easier for admins to just grant credentials for everything rather than sorting through each request and granting access for specific tasks. But getting visibility into and control over permissions is vital to security. <\/p>\n<p>That also applies to service providers, whose activities should always be monitored. A provider accessing a server it&#8217;s not contracted to handle, or one that begins removing a treasure trove of data, should raise a red flag. There are many examples of attackers using compromised credentials from a service provider to steal data or cause significant damage. As such, access for service providers should always be carefully controlled. <\/p>\n<p><strong>Don&#8217;t Set and Forget an Incident Response Plan<\/strong><br \/>A cybersecurity strategy must emphasize resiliency, so an incident response plan must cover factors ranging from data recovery, business response and communications to cyber-insurance processes and dealing with regulators. As the responses to <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/china-based-threat-actor-apt10-ramps-up-cyber-espionage-activity\" target=\"_blank\" rel=\"noopener\">Operation Cloud Hopper<\/a> and NotPetya showed \u2014 and the White House&#8217;s <a href=\"https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2021\/05\/12\/executive-order-on-improving-the-nations-cybersecurity\/\" target=\"_blank\" rel=\"noopener\">Executive Order<\/a> on cybersecurity mandates \u2014 it&#8217;s also essential to be prepared to share threat information as part of a unified response. Supply chain attacks like SolarWinds cut across organizational boundaries; the response has to involve multiple sectors.<\/p>\n<p>Internally, it&#8217;s also important to conduct incident response exercises that cover data recovery and reparation. You should also try and think about how to act in every possible situation. And don&#8217;t forget about contingency plans in case something unexpected happens. What happens, for instance, if the data backups used for recovery are the target of an attack? Finally, don&#8217;t rely solely on your detection tools to pick up known vulnerabilities for incident response.<\/p>\n<p>Cybersecurity has never been easy, but in today&#8217;s environment securing servers and internal systems is a relatively easy win. The hard part is third-party risk. Organizations need to conduct third-party assessments, enforce strict least-privilege policies and continuously monitor activity. And it&#8217;s best to build that security posture from the ground up, starting with making sure you have the basics of cloud security covered. Because, if you&#8217;re struggling with the basics, you&#8217;re not going to get to the advanced levels of security.<\/p>\n<p>Read More <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Nearly every organization should assume that it is at risk, but there are ways of countering the tactics used by advanced persistent threats.Read More <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\">HERE<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[151],"tags":[],"class_list":["post-45054","post","type-post","status-publish","format-standard","hentry","category-darkreading-ti"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Navigating Nobelium: Lessons From Cloud Hopper &amp; NotPetya 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Navigating Nobelium: Lessons From Cloud Hopper &amp; NotPetya 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-01-28T15:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt481ce449947cf4f5\/61eb1b0ba3de30188f4f0b5e\/SecurityLock_vska_Alamyjpg.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Navigating Nobelium: Lessons From Cloud Hopper &amp; NotPetya\",\"datePublished\":\"2022-01-28T15:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\\\/\"},\"wordCount\":970,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt481ce449947cf4f5\\\/61eb1b0ba3de30188f4f0b5e\\\/SecurityLock_vska_Alamyjpg.jpg\",\"articleSection\":[\"DarkReading |TI\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\\\/\",\"name\":\"Navigating Nobelium: Lessons From Cloud Hopper &amp; NotPetya 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt481ce449947cf4f5\\\/61eb1b0ba3de30188f4f0b5e\\\/SecurityLock_vska_Alamyjpg.jpg\",\"datePublished\":\"2022-01-28T15:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\\\/#primaryimage\",\"url\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt481ce449947cf4f5\\\/61eb1b0ba3de30188f4f0b5e\\\/SecurityLock_vska_Alamyjpg.jpg\",\"contentUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt481ce449947cf4f5\\\/61eb1b0ba3de30188f4f0b5e\\\/SecurityLock_vska_Alamyjpg.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Navigating Nobelium: Lessons From Cloud Hopper &amp; NotPetya\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Navigating Nobelium: Lessons From Cloud Hopper &amp; NotPetya 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\/","og_locale":"en_US","og_type":"article","og_title":"Navigating Nobelium: Lessons From Cloud Hopper &amp; NotPetya 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-01-28T15:00:00+00:00","og_image":[{"url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt481ce449947cf4f5\/61eb1b0ba3de30188f4f0b5e\/SecurityLock_vska_Alamyjpg.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Navigating Nobelium: Lessons From Cloud Hopper &amp; NotPetya","datePublished":"2022-01-28T15:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\/"},"wordCount":970,"commentCount":0,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt481ce449947cf4f5\/61eb1b0ba3de30188f4f0b5e\/SecurityLock_vska_Alamyjpg.jpg","articleSection":["DarkReading |TI"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.threatshub.org\/blog\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\/","url":"https:\/\/www.threatshub.org\/blog\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\/","name":"Navigating Nobelium: Lessons From Cloud Hopper &amp; NotPetya 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt481ce449947cf4f5\/61eb1b0ba3de30188f4f0b5e\/SecurityLock_vska_Alamyjpg.jpg","datePublished":"2022-01-28T15:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\/#primaryimage","url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt481ce449947cf4f5\/61eb1b0ba3de30188f4f0b5e\/SecurityLock_vska_Alamyjpg.jpg","contentUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt481ce449947cf4f5\/61eb1b0ba3de30188f4f0b5e\/SecurityLock_vska_Alamyjpg.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/navigating-nobelium-lessons-from-cloud-hopper-notpetya\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Navigating Nobelium: Lessons From Cloud Hopper &amp; NotPetya"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/45054","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=45054"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/45054\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=45054"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=45054"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=45054"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}