IBM Security X-Force reported a global spear-phishing campaign targeting organizations involved in the COVID-19 vaccine cold chain, using emails that impersonated a Haier Biomedical executive and malicious HTML attachments themed as requests for quotation to steal credentials. The activity began in September 2020 and hit entities in at least six countries, including the European Commission’s Directorate-General for Taxation and Customs Union, with IBM assessing that the operation was likely intended to support follow-on unauthorized access and cyber espionage tied to vaccine distribution.
Subsequent reporting indicated the targeting extended across Europe, Asia, North America, and South America, affecting transportation, health care, information technology, electronics, refrigeration, manufacturing, and government organizations. IBM said the campaign showed precision targeting of individuals involved in import/export, transport, and public health, while victims included automotive, aviation, maritime, biomedical research, pharmaceutical, software, web-hosting, and outsourcing organizations; DHS CISA separately warned vaccine storage and transport entities to remain vigilant.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
IBM assessed that a global spear-phishing campaign began in September 2020 against organizations associated with the COVID-19 vaccine cold chain. The operation used emails impersonating a Haier Biomedical executive and RFQ-themed malicious HTML attachments to harvest credentials.
The X-Force Threat Intelligence Index 2021 reported that industries heavily relied upon for COVID-19 response efforts were at the epicenter of targeting during 2020, and that attacks on manufacturing, energy, and health care doubled from the previous year.
IBM noted that Gavi, UNICEF, and other partners launched the Cold Chain Equipment Optimization Platform (CCEOP), which later became relevant to the phishing lures used in the campaign.
IBM released indicators of compromise for the campaign, including malicious HTML attachment naming patterns, SHA-256 hashes, credential-harvesting and C2 URLs, and related DNS contact addresses and domains.
DHS CISA issued an alert in conjunction with IBM's research, urging vaccine storage and transport organizations to review the findings and recommended security practices.
After uncovering the operation, IBM said it followed responsible disclosure protocols and notified appropriate entities and authorities. IBM assessed the activity was likely intended to enable follow-on unauthorized access and possible cyber espionage, though it could not firmly attribute the campaign.
IBM later reported likely targeting of additional organizations connected to the COVID-19 supply chain across Europe, Asia, North America, and South America, including transportation, health care, IT and electronics, refrigeration, metal manufacturing, and European government entities. The activity included precision targeting of specific individuals in ministries and departments involved in transport, import/export, and public health functions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 77 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
ibm.com
Open sourcesecurityintelligence.com
Open sourcesecurityintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.