/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft says it detected three APTs, from N. Korea and Russia, that launched attacks on at least seven companies developing a COVID-19 vaccine or treatments

The three state-sponsored hacker groups (APTs) are Russia's Strontium (Fancy Bear) and North Korea's Zinc (Lazarus Group) and Cerium.

ZDNet Catalin Cimpanu

Context & Ripple Effects

Microsoft's disclosure lands two months after the US and UK publicly attributed ongoing vaccine-related cyberattacks to Russia's APT29, making this the second major government-linked campaign against coronavirus research that year — but the first to name three separate groups, Strontium from Russia and Zinc and Cerium from North Korea, hitting at least seven companies at once.

The report also extends a pattern Microsoft has documented before: it had already flagged Strontium targeting sporting and anti-doping organizations ahead of the Tokyo Olympics, and within weeks of this disclosure, sources reported suspected North Korean hackers posing as recruiters to go after vaccine maker AstraZeneca directly. Pandemic research had become a contested intelligence target for both Moscow and Pyongyang simultaneously.

First-order effects

  • At least seven companies developing COVID-19 vaccines or treatments are now defending against three named state-sponsored groups — Strontium, Zinc, and Cerium — meaning security teams at those firms must triage indicators from a Microsoft advisory rather than treat this as isolated intrusion attempts.
  • Microsoft positions itself as the primary public source of attribution on these campaigns, a role it also claimed with its later 'high confidence' linking of an infosec-researcher hacking spree to Zinc, the DPRK-affiliated group.

Second-order effects

  • Vaccine developers and their research partners face pressure to harden credential systems and phishing defenses against simultaneous Russian and North Korean tradecraft, since the July APT29 attribution and this disclosure show multiple states running parallel campaigns against the same sector.
  • Government cyber agencies in the US and UK, having already named APT29, gain corroboration for expanding warnings about nation-state interest in pharmaceutical supply chains — pushing smaller biotech firms without dedicated threat-intel teams into reliance on vendor advisories like Microsoft's.

Third-order effects

  • If the pattern holds, pandemic-era medical research becomes a standing target where rival nation-states operate concurrently against the same companies, normalizing continuous state espionage against pharma rather than episodic campaigns tied to single events like the Olympics or an election cycle.
  • Private-sector attribution — Microsoft naming specific APTs faster than governments — cements large cloud vendors as de facto intelligence publishers, shifting how companies and policymakers learn who is attacking critical industries.

The trend: State-sponsored hacking is converging on strategically valuable health research, with Microsoft's rapid private-sector attribution becoming the primary way the public learns which nations are involved.

Discussion

  • @lukolejnik Lukasz Olejnik on x
    Here it is! First corporate victim of debunked information about a “first death following ransomware infection” (that didn't happen but the Microsoft PR/Comms team was slow in appreciating it) https://blogs.microsoft.com/ ... https://twitter.com/...
  • @tarah @tarah on x
    Nation-state cyberattacks on health care professionals and people working to save humanity from #COVID19 must be answered. @Microsoft has a new report on three attackers, out today at the @ParisPeaceForum. https://blogs.microsoft.com/ ... https://twitter.com/...
  • @tomburt45 Tom Burt on x
    Cyberattacks targeting the healthcare sector are unconscionable and should be condemned by all civilized society. Today, we're sharing an update on recent nation-state attacks targeting companies combatting the COVID-19 pandemic. https://blogs.microsoft.com/ ...
  • @thegrugq Thaddeus E. Grugq on x
    Microsoft, this is just embarrassing. There are plenty of reasons to make a solid case for leaving the carenet alone without having to lie. https://twitter.com/...
  • @bradsmi Brad Smith on x
    Cyberattacks on healthcare institutions responding to the COVID-19 pandemic are unconscionable. We need world leaders to come together & condemn this behavior by affirming and enforcing international laws to protect frontline workers & critical research. https://blogs.microsoft.c…
  • @jamiemaccoll Jamie MacColl on x
    Microsoft framing what appears to be espionage/intelligence collection as ‘cyberattacks’ on vaccine researchers is unhelpful. Conflating espionage with sabotage is just going to serve to make people more frightened than is necessary: https://blogs.microsoft.com/ ...
  • @selenalarson Selena on x
    New blog from Microsoft details ongoing activity targeting COVID-19 researchers and vaccine development. Also goes hard on the need for international laws to protect healthcare facilities from cyberattacks. 👏https://blogs.microsoft.com/ ...
  • @gordoncorera Gordon Corera on x
    New-Microsoft says it detected cyberattacks from three nation-state actors targeting 7 companies involved in COVID vaccines and treatments in Canada, France, India, S Korea and US. Attacks came from Strontium (Russian group) and two groups from N Korea https://blogs.microsoft.com…
  • @nikolasott Nikolas Ott on x
    Out now: Microsoft has detected cyberattacks from three nation-state actors targeting seven prominent companies directly involved in researching vaccines and treatments for Covid-19. Learn more here: https://blogs.microsoft.com/ ...
  • @johnhultquist John Hultquist on x
    Call from @TomBurt45 of Microsoft for greater action against criminal and state healthcare threats. As numbers climb and healthcare capacity is overwhelmed this becomes more serious. https://blogs.microsoft.com/ ...
  • @ericgeller Eric Geller on x
    Russian and North Korean hackers have recently targeted seven “prominent companies” researching coronavirus treatments and vaccines, and in some cases the attacks were successful, Microsoft said today. https://subscriber.politicopro.com/ ... https://blogs.microsoft.com/ ...
  • @jrreed J.R. Reed on x
    In recent months, Microsoft has detected cyberattacks out of Russia and North Korea targeting 7 companies involved in researching COVID-19 vaccines and treatments. https://blogs.microsoft.com/ ...
  • @zackwhittaker Zack Whittaker on x
    New: Microsoft says hackers backed by Russia and North Korea have targeted COVID-19 vaccine makers. Microsoft said it blocked the majority of the attacks, but acknowledged some were successful. https://techcrunch.com/...