Block title

-

Coronavirus-themed security attacks on the increase

- Advertisment -

By Indi Siriniwasa, Vice President at Trend Micro Sub-Saharan Africa

When there is a crisis, there are those who will try and take advantage. Unfortunately, cybercriminals aren’t guided by the same moral compass as the rest of humanity. In fact, they are using the current COVID-19 pandemic to try and break through defences by using scare tactics and a variety of malicious campaigns including email spam, BEC, malware, ransomware, malicious domains, and sending seemingly helpful emails to spread infected files.

Many industries are using remote working as a means to reinforce social distancing, but that means users aren’t always behind their enterprise firewall, which is a problem. It is critical at this time that consumers and remote workers become even more cautious.

Spam
At a time like this, humans are starved for information and will turn to email to get it. But be careful, the coronavirus disease (COVID-19) is being used as bait in email spam attacks on targets around the globe. As the number of those afflicted continues to surge by the thousands, campaigns that use the disease as a lure likewise increase.

As of this week, Trend Micro Researchers uncovered 2814 instances of Coronavirus spam in South Africa alone. The data has been collected from almost 7 000 unique samples out of 41 000 total Corona phishing spam samples reported from Smart Protection Network (SPN) enabled in Trend Micro Messaging products.

In addition, Trend Micro researchers acquired email samples sent to and received from all over the globe, including countries such as the U.S., Japan, Russia and China. These emails are designed to look like they originated from an official health organisation and have updates, recommendations and safety tips. But unfortunately, they also contain malicious attachments.

One particular sample received by our team had the subject “Corona Virus Latest Updates” and claimed to come from the Ministry of Health in the U.S. It was in fact spoofed, contained malware, and was of no use at all. This is just one example. Others include delivery notices asking you to update details, access to a proposed vaccine, and emails asking you to update medical information.

Malware files
Then there are more blatant attacks; our Trend Micro researchers were also able to detect malware with “corona virus” in their filename, including:

  • CORONA VIRUS AFFECTED CREW AND VESSEL.xlsm
  • exe
  • LIST OF CORONA VIRUS VICTIM.exe
  • POEA HEALTH ADVISORY re-2020 Novel Corona Virus.pdf.exe

Malware files are also being seeded in fake news sites that purport to provide updates, dashboards and maps on the spread of the virus. One look at the sudden number of websites that now have the name “corona” in them, and you will see that there is a problem.

BEC
Our researchers were also alerted about a Business Email Compromise (BEC) attack mentioning coronavirus, which was reported by the Agari Cyber Intelligence Division (ACID). Spearheaded by a well-known BEC group called “Ancient Tortoise”, the threat actors targeted accounts receivables by getting them to forward old account reports.

The information was used to send targeted emails under the auspices of legitimate companies to try and collect data. Their hook? These cybercriminals were working under the guise that banking and payment methods needed to be updated in light of COVID-19.

Ransomware
Another example includes a new ransomware variant called CoronaVirus, spread through a site that proposed to assist with cleaning and optimising your system. The Malware HunterTeam exposed this instance.

Those who fell prey to this event unwittingly downloaded the WSGSetup.exe file from the fake site. The executable file inserted a malware downloader for the CoronaVirus ransomware as well as the password-stealing trojan, Kpot.

Secure your defences
Unfortunately, as much as we need to get people comfortable with the concept of working from home, and we have the tools to do so, we also need to arm them with the facts. We need to educate employees that these threats are real, and they may fall prey to disingenuous actors who are feeding off the untenable situation we find ourselves in as a result of this pandemic.

At Trend Micro, we are encouraging our partners and customers to play open cards with their employees, present them with the facts, and update them regularly of the current scams doing the rounds. Most importantly, ensure that the endpoints that are now accessing your systems remotely remain secure.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest articles

Coronavirus-themed security attacks on the increase

By Indi Siriniwasa, Vice President at Trend Micro Sub-Saharan Africa When there is a crisis, there are those who will try and take advantage. Unfortunately,...

IoT will become the biggest user of edge computing amidst increasing security concerns

From less than $1.5 billion in 2017 to an anticipated $9 billion by 2024, the worldwide edge computing market is set to show significant...

ICASA calls on licensees to make communication services more freely available, while making regulatory concessions

Considering the recent developments with regards to the spread of the COVID-19 pandemic, the Independent Communications Authority of South Africa (ICASA) has written to...

Nine South African students attended US Space and Rocket Centre for 10th annual space camp

Nine South African students recently travelled to the U.S. Space and Rocket Centre (USSRC) in Huntsville, Alabama, as part of the 10th annual Honeywell...

The global outbreak of COVID-19 has brought the world’s digital divide into sharp focus.

ITU News reports that the Internet is a vital communications tool for people and communities affected by the outbreak of the Coronavirus. As schools...

Cybersecurity in automotive industry presents a major challenge

Luxury vehicles are not exempt from cyber-attacks, even if a vehicle is designed with state-of-the art security and maintained with over-the-air software updates during...
- Advertisement -

Surveillance and security service providers must be PRiRA accredited

Any business operating as a surveillance or security service provider, be it for the installation, configuration, support and monitoring of CCTV equipment, for a...

Go cashless, boost SA’s informal sector and reduce COVID-19 spread

COVID-19 has unintentionally encouraged an increase in cashless spending. As a result of the World Health Organisation (WHO) announcement, people are being advised to...

Free coronavirus legal and risk guide

webberwentzel-coronavirus-bookletWebber Wentzel has prepared a legal and risk coronavirus guide in collaboration with their alliance partner, Linklaters. The guide offers practical tips to consider...

Space science: Cosmic rays are increasing at aviation altitudes

Over the past three years, cosmic radiation at aviation altitudes has increased by 12%. In January 2020, students of Earth to Sky Calculus and Spaceweather.com travelled to...

Ethical hacking now part of BT security advisory services

British Telecom (BT) Security’s ethical hacking team provides ‘penetration testing’ or ‘red team’ services, using the same tools and techniques as cybercriminals to attack...