Microsoft and Facebook disrupt ZINC malware attack to protect customers and the internet from ongoing cyberthreats
2017-12-19 • Microsoft •
Microsoft and Facebook worked with the security community to disrupt ZINC, also known as the Lazarus Group, after Microsoft concluded the actor was responsible for WannaCry. The response included disrupting malware used by the group, cleaning infected customer systems, disabling accounts used for attacks, and strengthening Windows defenses against reinfection. The excerpt notes coordinated public attribution by the United States, United Kingdom, Australia, Canada, New Zealand, and Japan to North Korea. The activity matters because it pairs private-sector disruption with government attribution for a nation-state actor that had affected civilian systems at scale.