Staff at British biopharmaceutical company AstraZeneca, which is conducting clinical trials of a coronavirus vaccine it developed jointly with the University of Oxford, were recently targeted by hackers.

According to Reuters, hackers from North Korea used LinkedIn and WhatsApp to target AstraZeneca employees with phishing emails containing malware. The emails the hackers sent were about new job openings and required recipients to download malicious documents disguised as job descriptions.
Given that the company is currently conducting clinical trials of a vaccine for COVID-19, the attack came as no surprise.
The UK recently purchased at least 5 million doses of a vaccine developed by Moderna, which claims to be around 95% effective, and has also secured 355 million doses of potential vaccines developed by other vaccine research organisations. The government is also monitoring trials of the vaccine developed by AstraZeneca and the University of Oxford.
Reuters has learned from reliable sources that North Korean hackers recently targeted a “wide range of people” at AstraZeneca, including staff involved in research on coronavirus vaccines. The tools and techniques used in the campaign made it clear that the attacks were part of an ongoing campaign conducted by North Korean hackers.

Responding to the report published by Reuters, the National Cyber Security Centre said it provides ongoing and proactive support to healthcare organisations in the UK and is fully committed to protecting the health sector and critical vaccine research and development from cyber threats.
Earlier this month, Microsoft had also issued a warning about the Russian Strontium and the North Korean Zinc and Cerium targeting organizations involved in COVID-19 vaccine research, using brute-force and spear-phishing techniques. The organizations targeted by the attacks are located in Canada, France, India, South Korea, and the United States.
The list of organizations mainly contains vaccine research organizations in various stages of clinical trials as well as organizations that have developed tests for COVID-19. Many of these organizations have benefited from government funding and contracts in many countries for work related to Covid-19. According to Tom Burt, Corporate Vice President for Customer Security & Trust at Microsoft, the two North Korean government hacking groups are also targeting COVID-19 research organizations with spear-phishing attacks that aim to exploit the human factor to obtain information about vaccine research.
