Microsoft threat intelligence presented at CyberWarCon 2022
2022-11-10 • Microsoft •
Microsoft’s CyberWarCon 2022 recap summarizes several threat-intelligence presentations, including a Microsoft and LinkedIn session on ZINC weaponizing open-source software. The source identifies ZINC as a North Korea-based actor and places the session within MSTIC’s broader work tracking nation-state activity and sharing defensive intelligence with customers and the security community. Because the blog also covers separate Russian and Chinese actor research, the DPRK-relevant archive takeaway is the ZINC session and its focus on abuse of legitimate open-source software rather than the unrelated BROMINE or China-focused findings.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://aka.ms/ukrainespecialre… | 2022-11-10 | 2022-11-10 |
Related Actors
Related Reports
2022-11-07 •
90% Match
#Trend
#Zinc
#DEV-0530
#Cerium
#Osmium
#Copernicium
#Plutonium
#DEV-0215
#T1053
Shares tag: Zinc • Same author: Microsoft • Published within a week
Shares tag: Zinc • Published within a month
Shares tag: Zinc • Same author: Microsoft
Shares tag: Zinc • Same author: Microsoft
Shares tag: Zinc • Same author: Microsoft
2017-12-19 •
70% Match
Microsoft and Facebook disrupt ZINC malware attack to protect customers and the internet from ongoing cyberthreats
Microsoft
Shares tag: Zinc • Same author: Microsoft