/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft wins court order to seize 50 domains run by North Korean cyber-espionage group Thallium, the fourth APT Microsoft has combated with this tactic

Microsoft takes control of 50 domains operated by Thallium (APT37), a North Korean cyber-espionage group.

ZDNet Catalin Cimpanu

Context & Ripple Effects

Microsoft's seizure of 50 Thallium domains is the fourth time it has used court orders to strip a nation-state hacking group of its infrastructure, extending a playbook that began with 99 websites tied to Iran's Phosphorus group in March 2019. The tactic has since become routine enough that Microsoft and industry partners used it mid-crisis to kill a command-and-control domain in the SolarWinds supply-chain hack.

What makes the Thallium action notable is cadence rather than novelty: within roughly three years the same legal instrument is being applied against Iranian, North Korean, Russian (Strontium's Ukraine-targeting domains) and Chinese (42 domains tied to a Chinese espionage group) operators — turning an emergency measure into a standing counter-intelligence capability held by a private company.

First-order effects

  • Thallium loses control of 50 operational domains at once, forcing the group to rebuild command-and-control infrastructure and re-establish contact with any targets whose traffic now lands on Microsoft-controlled servers.
  • Microsoft gains visibility into who was connecting to those domains, converting seized infrastructure into an intelligence asset for identifying victims and tracking the group's targeting.

Second-order effects

  • Other state-backed groups face higher infrastructure churn costs, since domains registered through US-linked registrars carry seizure risk that pushes them toward costlier or less reliable hosting.
  • Rival security vendors and cloud providers are pressured to match Microsoft's legal-aggression model or cede both threat intelligence and the customer trust that comes from visibly disabling attacker operations.

Third-order effects

  • If the pattern holds, court-ordered domain seizure hardens into a privatized enforcement layer for nation-state cyber operations, with a handful of large tech companies acting where governments' own takedown authorities stop.
  • The breadth of targets — four distinct state adversaries in as many years — points toward codification: regulators and courts will eventually need explicit frameworks for how much offensive disruption private firms may lawfully conduct.

The trend: Microsoft is institutionalizing court-ordered domain seizures as a repeatable counter-APT playbook, applying one legal template against Iranian, North Korean, Russian and Chinese state hackers alike.

Discussion

  • @tomburt45 Tom Burt on x
    Microsoft's DCU team has taken legal action to protect our customers from a nation-state group that we call Thallium, operating out of North Korea. Read more about our actions and the steps you can take to protect yourself from cyberthreats here: https://blogs.microsoft.com/ ...
  • @blaw @blaw on x
    A group of hackers with ties to North Korea targets Microsoft software users by impersonating the company, according to a lawsuit in Virginia federal court. https://news.bloomberglaw.com/ ...
  • @rungrage Pukhraj Singh on x
    Peak 2019. Microsoft takes a North Korean threat actor to a district court. Couple of issues: if it was state-to-state espionage, then this may actually be counterproductive. If indeed this is espionage, then singling out NK could also be inequitable https://blogs.microsoft.com/ …
  • @w7voa Steve Herman on x
    Court orders allow @Microsoft to take control of 50 domains used by #Thallium hacking group, believed to operate from the #DPRK, which targeted government employees, think tanks, university staffers and individuals working on nuclear proliferation issues.https://blogs.microsoft.c…
  • @cristingoodwin Cristin Goodwin on x
    Proud of the work my DCU and MSTIC colleagues are driving to use the courts to disrupt Nation State attacks, like this one against Thallium. https://blogs.microsoft.com/ ...
  • @campuscodi Catalin Cimpanu on x
    Microsoft takes down 50 domains operated by Thallium (APT37), a North Korean APT * MSFT wins court order to seize domains * Fourth APT against which this tactic proved successful * First three were Barium (🇨🇳), APT28 (🇷🇺), and APT35 (🇮🇷) https://www.zdnet.com/... https://twitter.…