• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Internet

The Internet is drowning in COVID-19-related malware and phishing scams

March 16, 2020
Share on FacebookShare on Twitter

Emails and websites are promising vital information about keeping safe from the coronavirus pandemic that’s sweeping the globe and threatening millions. In fact, a flood of them are scams that push malware, ransomware, and disinformation; attempt to steal passwords and personal information; and conduct espionage operations by hackers working for nation-states.

One of the most recent coronavirus hoaxes to come to light is an Android app available at coronavirusapp[.]site. It claims to provide access to a map that provides real-time virus-tracking and information, including heatmap visuals and statistics. In fact, a researcher from DomainTools said, the app is laced with ransomware.

“This Android ransomware application, previously unseen in the wild, has been titled ‘CovidLock’ because of the malware’s capabilities and its background story,” DomainTools researcher Tarik Saleh wrote in Friday’s report. “CovidLock uses techniques to deny the victim access to their phone by forcing a change in the password used to unlock the phone. This is also known as a screen-lock attack and has been seen before on Android ransomware.”

CovidLock charges about $100 in bitcoins to unlock infected devices. Since version 7, Android has provided protection against screen-lockout attacks but only if users have set a password to lock their device screens to begin with. DomainTools researchers have reverse engineered the ransomware and plan to release decryption keys that will unlock phones for free. DomainTools didn’t say how many devices have been infected.

Gone phishin’

People pushing phishing scams are also capitalizing on the pandemic. One batch of emails sent to college students poses as official communications from University personnel offering bogus updates about closures and other coronavirus-related news. A variation of this type of email purports to come from employers and targets people who are working from home. In reality, both scams provide links to fake OneDrive or Office365 login screens that capture user credentials.

Yet another phishing scam appears to come from the World Health Organization. According to researchers from security firm Kaspersky Lab, the emails promise information on safety measures to avoid infection. Recipients who click on an embedded link visit a site that prompts them to share personal information. The scam looks more realistic than previous coronavirus phishing campaigns Kaspersky Lab has found. The firm found other scams that claimed to offer face masks and included malware attachments.

Nation-states are also milking the coronavirus scare. According to security firm FireEye, hackers working for the governments of China, Russia, and North Korea are also using virus-related content to conduct espionage operations.

Researchers from Sophos, meanwhile, have identified dozens of malicious websites with domains that reference COVID or COVID-19, the disease caused by the coronavirus.

Online scams that are tailored to major news events have been around for more than a decade. Normally, however, they tend to morph relatively quickly from one breaking event to another. With the coronavirus commanding an almost unprecedented amount of coverage around the world, these latest campaigns have been nothing short of a flurry of attacks that show no signs of slowing down.

Readers should be highly skeptical of emails and websites that purport to provide information or goods related to the ongoing pandemic. The key fact to confirm is the primary source of those communications. Readers should never take source claims at face value. One of the most reliable sources for legitimate coronavirus-related information is this page from the US Centers for Disease Control and Prevention. Communications from local departments of health can also be helpful, but only when the emails or websites can be confirmed as coming from a legitimate agency. These departments can usually be found through Web searches—for instance, the San Francisco Department of Health.

Next Post

Amazon Echo vs. Dot vs. Show vs. Plus: Which should you buy in 2020?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • Review: Fatal Frame II: Crimson Butterfly Remake (Nintendo Switch 2) – Digitally Downloaded
  • Inflation comes to Fortnite: V-Bucks prices increase
  • PSA: Samsung Galaxy S26 series pre-order offers end tonight!
  • Clarity as strategy
  • Best party speaker deal: Save 17% on the Sony ULT Tower 9 Bluetooth Karaoke Party Speaker

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously