Friday, June 13, 2025
HomeCyber AttackNorth Korean Hackers Targeted COVID Vaccine Maker AstraZeneca

North Korean Hackers Targeted COVID Vaccine Maker AstraZeneca

Published on

SIEM as a Service

Follow Us on Google News

British pharmaceutical company AstraZeneca, one of the manufacturers leading the way towards developing a Covid-19 vaccine, has been targeted by North Korean hackers. 

Suspected North Korean hackers have tried to break into the systems of AstraZeneca in recent weeks, two people with knowledge of the matter informed Reuters.

The hackers posed as recruiters on LinkedIn and WhatsApp and approached AstraZeneca staff with fake job offers. The documents purporting to be job descriptions were laced with “malicious code designed to gain access to a victim’s computer,” according to the report.

- Advertisement - Google News

Though they were not successful, the attacks targeted a broad set of people, including staff working on COVID-19 research. The North Korean mission to the United Nations in Geneva reportedly declined to discuss the allegations.

The sources said Reuters “The tools and techniques used in the attacks showed they were a part of an ongoing hacking campaign that U.S. officials and cybersecurity researchers have attributed to North Korea.”

The campaign has previously focused on defense companies and media organizations but pivoted to COVID-related targets in recent weeks, according to three people who have investigated the attacks.

Targeting vaccines

Microsoft said this month it had seen two North Korean hacking groups target vaccine developers in multiple countries, including by “sending messages with fabricated job descriptions.” Microsoft did not name any of the targeted organizations.

South Korean lawmakers said, that the country’s intelligence agency had foiled a number of those attempts.

Reuters has previously reported that hackers from Iran, China, and Russia have attempted to break into leading drugmakers and even the World Health Organisation this year. Tehran, Beijing, and Moscow have all denied the allegations.

Some of the accounts used in the attacks on AstraZeneca were registered to Russian email addresses, one among the sources said, during a possible plan to mislead investigators.

North Korea has been blamed for a few of the most foremost cyber incidents, including the 2014 attack on Sony Pictures deployed in retaliation for the blockbuster movie “The Interview,” the global WannaCry ransomware pandemic in 2017, and many others.

Pyongyang has described the allegations as a part of attempts by Washington to smear its image.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Also Read

COVID-19 Research Organizations Attacked by Chinese Hackers Group

The Importance of Cybersecurity in The Post-COVID-19 World

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Major Outage Hits Google Cloud and Linked Cloudflare Services, Thousands Affected

On June 12, 2025, concurrent infrastructure failures at Cloudflare and Google caused widespread service...

TokenBreak Exploit Tricks AI Models Using Minimal Input Changes

HiddenLayer’s security research team has uncovered TokenBreak, a novel attack technique that bypasses AI...

WebDAV Remote Code Execution 0-Day Actively Exploited — PoC Released

A critical zero-day vulnerability in Microsoft’s Web Distributed Authoring and Versioning (WebDAV) protocol, tracked...

Cybercriminals Exploiting Expired Discord Invite Links to Deploy Multi-Stage Malware

Recent investigations by Check Point Research have uncovered a sophisticated malware campaign that leverages...

Credential Abuse: 15-Min Attack Simulation

Credential Abuse Unmasked

Credential abuse is #1 attack vector in web and API breaches today (Verizon DBIR 2025). Join our live, 15-min attack simulation with Karthik Krishnamoorthy (CTO - Indusface) and Phani Deepak Akella (VP of Marketing - Indusface) to see hackers move from first probe to full account takeover.

Discussion points


Username & email enumeration – how a stray status-code reveals valid accounts.
Password spraying – low-and-slow guesses that evade basic lockouts.
Credential stuffing – lightning-fast reuse of breach combos at scale.
MFA / session-token bypass – sliding past second factors with stolen cookies.

More like this

Major Outage Hits Google Cloud and Linked Cloudflare Services, Thousands Affected

On June 12, 2025, concurrent infrastructure failures at Cloudflare and Google caused widespread service...

TokenBreak Exploit Tricks AI Models Using Minimal Input Changes

HiddenLayer’s security research team has uncovered TokenBreak, a novel attack technique that bypasses AI...

WebDAV Remote Code Execution 0-Day Actively Exploited — PoC Released

A critical zero-day vulnerability in Microsoft’s Web Distributed Authoring and Versioning (WebDAV) protocol, tracked...