/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google's Threat Analysis Group shares a report outlining efforts by over 12 state-sponsored hackers using COVID-19 as cover for espionage

Lily Hay Newman / Wired :

Wired Lily Hay Newman

Context & Ripple Effects

This report is an early entry in what became Google's Threat Analysis Group's standing public-disclosure practice: naming state-backed actors as they surface, rather than waiting for government advisories. Within weeks, TAG followed up with Indian hack-for-hire firms spoofing WHO Gmail accounts for spearphishing, extending the same pandemic-themed targeting.

The report also set the baseline for TAG's later accounting of scale — by late 2021 it said it tracks 270+ state-backed threat actors and was sending rising volumes of phishing alerts to Gmail users — making this 12-group COVID snapshot the template for how the team frames attribution publicly.

First-order effects

  • Targeted Gmail users — government, healthcare, and research staff already stretched by the pandemic response — receive TAG's warning banners against phishing lures dressed up as COVID-19 correspondence from the WHO and health authorities.
  • The 12+ named state-sponsored groups lose the anonymity their campaigns relied on, forcing them to rotate infrastructure and personas mid-operation.

Second-order effects

  • Health agencies and pandemic-response organizations become a proven target category, pushing security teams at hospitals and research bodies to harden email and credential flows against impersonation of official health institutions.
  • Other platform security teams and threat-intel vendors face pressure to match TAG's disclosure cadence, turning public attribution into a competitive signal among the major cloud and email providers.

Third-order effects

  • Crisis events harden into standing attack surface: the pattern of espionage riding a global emergency foreshadows the later [[a:1170979|Chinese-linked campaign against US and Canadian academic, medical, and military research institutions]], where health and research targets remained the focus long after the pandemic pretext faded.
  • Private-sector threat intelligence groups like TAG consolidate their role as the de facto public channel for state-hacker attribution — a function governments historically owned — shaping how policymakers and the public learn about espionage campaigns.

The trend: State-sponsored espionage is increasingly piggybacking on global crises and health-research targets, with platform threat-intelligence teams like Google's TAG becoming the primary public disclosure channel for attribution.

Discussion

  • @z3rotrust Ian on x
    “There's arguably never been a better time to be a government hacker,” & “This is beyond the wildest dreams of the attacker in terms of the scale of remote work,” https://www.wired.com/... via @wired
  • @mrisher Mark Risher on x
    Hackers are tailoring their attacks to capitalize on coronavirus and working-from-home. @ShaneHuntley and our Threat Analysis Group just published on trends we're tracking https://blog.google/...
  • @razhael Raphael Satter on x
    Blog post calls out one campaign targeting US government employees with COVID-themed phishing offering free meals & coupons. https://www.blog.google/...
  • @ryanaraine Ryan Naraine on x
    Google has discovered more than a dozen *government-backed* attacker groups using COVID-19 themes as lure for phishing and malware attacks https://blog.google/...
  • @razhael Raphael Satter on x
    I guess this brings to three the number of APT groups said to have targeted @WHO in recent weeks: DarkHotel: https://www.reuters.com/... Charming Kitten: https://www.reuters.com/... Packrat: https://www.blog.google/... Spare a thought for their CISO.
  • @jenn_elias @jenn_elias on x
    “Our security systems have detected fake solicitations for charities and NGOs, to messages that try to mimic employer communications to employees working from home, to websites posing as official government pages and public health agencies.” https://blog.google/...
  • @campuscodi Catalin Cimpanu on x
    Google TAG published a report today saying they're tracking “over a dozen” of APTs using COVID lures. Confirms an older report/article of mine from March. Six weeks ago it was only 4 APTs. https://www.blog.google/... https://twitter.com/...