Zinc

2017-12-19 • MicrosoftMicrosoft and Facebook disrupt ZINC malware attac…

ZINC is Microsoft’s former designation for the North Korean threat actor also known as Lazarus Group. Microsoft publicly used the name in December 2017 while announcing coordinated disruption of the group’s malware, infrastructure, and attacker accounts. The governments of the United States, United Kingdom, Australia, Canada, New Zealand, and Japan attributed ZINC’s activity to North Korea, and Microsoft concluded that the actor was responsible for the destructive WannaCry outbreak of May 2017. Later Microsoft reporting documented ZINC targeting security researchers, technology companies, media organizations, and defense and aerospace employees through tailored social engineering. The group has posed as recruiters over professional networks and messaging services, delivered trojanized open-source applications and malicious job assessments, and deployed custom malware for reconnaissance, persistence, command execution, credential theft, and data collection. ZINC combines trusted-persona deception, software weaponization, and destructive or espionage-oriented operations against strategically valuable victims.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster