The malware found is an executable program (EXE) using file names such as ‘Corona’s domestic status’ and ‘Corona’s real-time corona status.’ When you run the file, you will see a pop-up window titled “Real-time Corona19 Status” depending on the variant.
The pop-up window shows four items and the corresponding numerical information, such as confirming patient, release (cure), death, and under test, as it shows actual corona 19 (coronavirus, COVID19) infection status. However, the malicious program automatically installs malicious code in the PC temporary folder without your knowledge.
Malware generated the PC has the function to perform the actual malicious behavior, and when infected, the user’s PC is exposed to various attacks such as ▲ remote control ▲ ▲ screen capture ▲ additional malware installation ▲ information takeover.
Est Security said that the program has a fixed number of all four items representing infected information, all at 100, and that the command control server (C2) uses a private IP address.
In particular, it has been reported that there have been no cases of infection reported through security’s public vaccine ”. However, the malicious program contains the actual RAT malicious module, so it cannot be ruled out that there is no possibility of threat of similar variants.
About the author: 최형주 Hyung-Joo, Choi Editor
The original post is available on the Secun website:
http://www.cctvnews.co.kr/news/articleList.html
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – coronavirus, Corona 19)
[adrotate banner=”5″]
[adrotate banner=”13″]
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best…
Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…
A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…
A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…
Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code…
This website uses cookies.