North Korean Hackers Targeted COVID Vaccine Maker AstraZeneca

British pharmaceutical company AstraZeneca, one of the manufacturers leading the way towards developing a Covid-19 vaccine, has been targeted by North Korean hackers. 

Suspected North Korean hackers have tried to break into the systems of AstraZeneca in recent weeks, two people with knowledge of the matter informed Reuters.

The hackers posed as recruiters on LinkedIn and WhatsApp and approached AstraZeneca staff with fake job offers. The documents purporting to be job descriptions were laced with “malicious code designed to gain access to a victim’s computer,” according to the report.

Though they were not successful, the attacks targeted a broad set of people, including staff working on COVID-19 research. The North Korean mission to the United Nations in Geneva reportedly declined to discuss the allegations.

The sources said Reuters “The tools and techniques used in the attacks showed they were a part of an ongoing hacking campaign that U.S. officials and cybersecurity researchers have attributed to North Korea.”

The campaign has previously focused on defense companies and media organizations but pivoted to COVID-related targets in recent weeks, according to three people who have investigated the attacks.

Targeting vaccines

Microsoft said this month it had seen two North Korean hacking groups target vaccine developers in multiple countries, including by “sending messages with fabricated job descriptions.” Microsoft did not name any of the targeted organizations.

South Korean lawmakers said, that the country’s intelligence agency had foiled a number of those attempts.

Reuters has previously reported that hackers from Iran, China, and Russia have attempted to break into leading drugmakers and even the World Health Organisation this year. Tehran, Beijing, and Moscow have all denied the allegations.

Some of the accounts used in the attacks on AstraZeneca were registered to Russian email addresses, one among the sources said, during a possible plan to mislead investigators.

North Korea has been blamed for a few of the most foremost cyber incidents, including the 2014 attack on Sony Pictures deployed in retaliation for the blockbuster movie “The Interview,” the global WannaCry ransomware pandemic in 2017, and many others.

Pyongyang has described the allegations as a part of attempts by Washington to smear its image.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Also Read

COVID-19 Research Organizations Attacked by Chinese Hackers Group

The Importance of Cybersecurity in The Post-COVID-19 World

Guru baran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

NETGEAR buffer Overflow Vulnerability Let Attackers Bypass Authentication

Some router models have identified a security vulnerability that allows attackers to bypass authentication. To exploit this vulnerability, an attacker…

1 day ago

5000+ CrushFTP Servers Hacked Using Zero-Day Exploit

Hackers often target CrushFTP servers as they contain sensitive data and are used for file sharing and storage. This makes…

1 day ago

13,142,840 DDoS Attacks Targeted Organization Around The Globe

DDoS attacks are a significant and growing risk that can overpower websites, crash servers, and block out authorized users with…

1 day ago

Hackers Exploit Old Microsoft Office 0-day to Deliver Cobalt Strike

Hackers have leveraged an old Microsoft Office vulnerability, CVE-2017-8570, to deploy the notorious Cobalt Strike Beacon, targeting systems in Ukraine.…

2 days ago

Microsoft Publicly Releases MS-DOS 4.0 Source Code

In a historic move, Microsoft has made the source code for MS-DOS 4.0, one of the most influential operating systems…

2 days ago

New SSLoad Malware Combined With Tools Hijacking Entire Network Domain

A new attack campaign has been discovered to be employed by the FROZEN#SHADOW, which utilized SSLoad malware for its operations…

2 days ago