The malware found is an executable program (EXE) using file names such as ‘Corona’s domestic status’ and ‘Corona’s real-time corona status.’ When you run the file, you will see a pop-up window titled “Real-time Corona19 Status” depending on the variant.
The pop-up window shows four items and the corresponding numerical information, such as confirming patient, release (cure), death, and under test, as it shows actual corona 19 (coronavirus, COVID19) infection status. However, the malicious program automatically installs malicious code in the PC temporary folder without your knowledge.
Malware generated the PC has the function to perform the actual malicious behavior, and when infected, the user’s PC is exposed to various attacks such as ▲ remote control ▲ ▲ screen capture ▲ additional malware installation ▲ information takeover.
Est Security said that the program has a fixed number of all four items representing infected information, all at 100, and that the command control server (C2) uses a private IP address.
In particular, it has been reported that there have been no cases of infection reported through security’s public vaccine ”. However, the malicious program contains the actual RAT malicious module, so it cannot be ruled out that there is no possibility of threat of similar variants.
About the author: 최형주 Hyung-Joo, Choi Editor
The original post is available on the Secun website:
http://www.cctvnews.co.kr/news/articleList.html
[adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – coronavirus, Corona 19)
[adrotate banner=”5″]
[adrotate banner=”13″]
Hot Topic suffered credential stuffing attacks that exposed customers' personal information and partial payment data.…
Cisco addressed multiple vulnerabilities in IOS and IOS XE software that can be exploited to…
Google's Threat Analysis Group (TAG) and Mandiant reported a surge in the number of actively…
Google addressed two zero-day vulnerabilities in the Chrome web browser that have been demonstrated during…
The INC Ransom extortion group hacked the National Health Service (NHS) of Scotland and is threatening…
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Microsoft SharePoint vulnerability disclosed at the…
This website uses cookies.