/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft says it detected three APTs, from N. Korea and Russia, that launched attacks on at least seven companies developing a COVID-19 vaccine or treatments

The three state-sponsored hacker groups (APTs) are Russia's Strontium (Fancy Bear) and North Korea's Zinc (Lazarus Group) and Cerium.

ZDNet Catalin Cimpanu

Context & Ripple Effects

Microsoft's disclosure lands five months after the US and UK publicly blamed Russia's APT29 for an ongoing campaign against coronavirus vaccine developers (joint attribution of APT29), extending the picture from one Russian group to three state-sponsored actors — Strontium on the Russian side, Zinc and Cerium for North Korea. It also fits a longer Microsoft pattern of naming Strontium operations well before victims do, as with the targeting of anti-doping organizations ahead of the Tokyo Olympics.

The timing matters because the target set is the most valuable intellectual property of 2020: at least seven companies working on vaccines or treatments, a list that independent reporting soon suggested included AstraZeneca, later described as being probed by North Korean operatives posing as recruiters on LinkedIn and WhatsApp (AstraZeneca recruiter-impersonation campaign).

First-order effects

  • Security teams at the seven targeted vaccine and treatment companies must now defend against three distinct adversaries simultaneously — Strontium, Zinc, and Cerium — each with different tradecraft, rather than a single attributed threat.
  • Microsoft positions its Threat Intelligence Center as the de facto early-warning channel for the pharmaceutical sector, since its detection preceded any victim disclosure.

Second-order effects

  • North Korea's interest proves durable beyond this campaign: the same Zinc group was later tied with high confidence to attacks on infosec researchers (ZINC's campaign against security researchers) and to a Chromium zero-day used for crypto theft (Lazarus Chromium zero-day exploitation), forcing defenders to treat DPRK groups as a persistent cross-sector problem.
  • Vaccine makers' security budgets and government cyber-assistance programs tilt toward the pharma supply chain, as national attributions — first APT29, now three more groups — make vaccine IP a formally recognized state-targeting priority.

Third-order effects

  • If rival powers keep converging on the same research targets, pandemic-era biotech joins elections and critical infrastructure as a standing category of state espionage, normalizing routine public attribution by private vendors like Microsoft alongside government advisories.
  • Sustained multi-state pressure on a single industry accelerates consolidation of threat-intel sharing between Big Tech and health-sector firms, with vendor-named APT catalogs becoming the shared vocabulary regulators and insurers build on.

The trend: State-sponsored espionage is institutionalizing around strategic research targets, with Microsoft's public APT attributions becoming the recurring mechanism through which vaccine-era campaigns are named and coordinated against.

Discussion

  • @lukolejnik Lukasz Olejnik on x
    Here it is! First corporate victim of debunked information about a “first death following ransomware infection” (that didn't happen but the Microsoft PR/Comms team was slow in appreciating it) https://blogs.microsoft.com/ ... https://twitter.com/...
  • @tarah @tarah on x
    Nation-state cyberattacks on health care professionals and people working to save humanity from #COVID19 must be answered. @Microsoft has a new report on three attackers, out today at the @ParisPeaceForum. https://blogs.microsoft.com/ ... https://twitter.com/...
  • @tomburt45 Tom Burt on x
    Cyberattacks targeting the healthcare sector are unconscionable and should be condemned by all civilized society. Today, we're sharing an update on recent nation-state attacks targeting companies combatting the COVID-19 pandemic. https://blogs.microsoft.com/ ...
  • @thegrugq Thaddeus E. Grugq on x
    Microsoft, this is just embarrassing. There are plenty of reasons to make a solid case for leaving the carenet alone without having to lie. https://twitter.com/...
  • @bradsmi Brad Smith on x
    Cyberattacks on healthcare institutions responding to the COVID-19 pandemic are unconscionable. We need world leaders to come together & condemn this behavior by affirming and enforcing international laws to protect frontline workers & critical research. https://blogs.microsoft.c…
  • @jamiemaccoll Jamie MacColl on x
    Microsoft framing what appears to be espionage/intelligence collection as ‘cyberattacks’ on vaccine researchers is unhelpful. Conflating espionage with sabotage is just going to serve to make people more frightened than is necessary: https://blogs.microsoft.com/ ...
  • @selenalarson Selena on x
    New blog from Microsoft details ongoing activity targeting COVID-19 researchers and vaccine development. Also goes hard on the need for international laws to protect healthcare facilities from cyberattacks. 👏https://blogs.microsoft.com/ ...
  • @gordoncorera Gordon Corera on x
    New-Microsoft says it detected cyberattacks from three nation-state actors targeting 7 companies involved in COVID vaccines and treatments in Canada, France, India, S Korea and US. Attacks came from Strontium (Russian group) and two groups from N Korea https://blogs.microsoft.com…
  • @nikolasott Nikolas Ott on x
    Out now: Microsoft has detected cyberattacks from three nation-state actors targeting seven prominent companies directly involved in researching vaccines and treatments for Covid-19. Learn more here: https://blogs.microsoft.com/ ...
  • @johnhultquist John Hultquist on x
    Call from @TomBurt45 of Microsoft for greater action against criminal and state healthcare threats. As numbers climb and healthcare capacity is overwhelmed this becomes more serious. https://blogs.microsoft.com/ ...
  • @ericgeller Eric Geller on x
    Russian and North Korean hackers have recently targeted seven “prominent companies” researching coronavirus treatments and vaccines, and in some cases the attacks were successful, Microsoft said today. https://subscriber.politicopro.com/ ... https://blogs.microsoft.com/ ...
  • @jrreed J.R. Reed on x
    In recent months, Microsoft has detected cyberattacks out of Russia and North Korea targeting 7 companies involved in researching COVID-19 vaccines and treatments. https://blogs.microsoft.com/ ...
  • @zackwhittaker Zack Whittaker on x
    New: Microsoft says hackers backed by Russia and North Korea have targeted COVID-19 vaccine makers. Microsoft said it blocked the majority of the attacks, but acknowledged some were successful. https://techcrunch.com/...