Categories: SecurityWorkspace

Scammers Use Coronavirus Map To Spread Malware

Security researchers have uncovered a malware scheme hidden behind a world map of coronavirus cases, as scammers look to take advantage of fear around the epidemic.

The scam comes to light as world coronavirus cases pass 100,000 for the first time, causing damage to global supply chains and weighing on share prices.

Last month researchers uncovered a number of email-based scams using the coronavirus as bait, but the latest malware is unusual in that it lies in wait on a website and doesn’t rely on email spam to lure potential victims.

The malware, with the filename corona.exe, hides in a website that supposedly shows updated coronavirus cases on a global map, Malwarebytes said.

Image credit: Malwarebytes

Payment cards swiped

The corona.exe file attempts to install itself on the sytems of those visiting the site in order to steal logins and payment card information.

The malware is a variant of AzorUlt, a family of spyware that steals information and sometimes downloads additional malware, Malwarebytes said.

As a result, the company first named the malware Trojan.Corona, but later renamed it Spyware.AzorUlt.

“Unlike similar coronavirus scams we discovered last month, this threat does not rely on an email campaign,” the company said in an advisory.

Last month researchers warned of several malware campaigns specifically leveraging the fear around the worldwide coronavirus outbreak, including a campaign in Japan that included malicious Word documents allegedly containing information about coronavirus prevention.

Email scams

Malware embedded in PDFs, MP4s and Docx files also circulated online, with titles alluding to virus protection tips.

The company spotted phishing emails that supposedly came from the US US Centres for Disease Control and Prevention (CDC), while another scam directed users to a fake donation page to help support government and medical research.

“All of these threats rely on the same dangerous intersection of misinformation and panic — a classic and grotesque cybercrime tactic,” Malwarebytes said.

The company advised users not to click on links in dubious emails and not to donate to causes they have not already vetted outside their email client.

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Hate Speech Watchdog CCDH To Quit Musk’s X

Target for Elon Musk's lawsuit, hate speech watchdog CCDH, announces its decision to quit X…

7 hours ago

Meta Fined €798m Over Alleged Facebook Marketplace Violations

Antitrust penalty. European Commission fines Meta a hefty €798m ($843m) for tying Facebook Marketplace to…

8 hours ago

Elon Musk Rebuked By Italian President Over Migration Tweets

Elon Musk continues to provoke the ire of various leaders around the world with his…

9 hours ago

VW, Rivian Launch Joint Venture, As Investment Rises To $5.8 Billion

Volkswagen and Rivian officially launch their joint venture, as German car giant ups investment to…

10 hours ago

AMD Axes 4 Percent Of Staff, Amid AI Chip Focus

Merry Christmas staff. AMD hands marching orders to 1,000 employees in the led up to…

13 hours ago

Tesla Recalls 2,431 Cybertrucks Over Propulsion Issue

Recall number six in 2024 for Tesla Cybertruck, and this time the fault cannot be…

14 hours ago