Microsoft warns of "prolific" Trickbot malware exploiting COVID-19 crisis

Hackers are sending out hundreds of emails offering free advice and testing

Trojan

Microsoft has warned that cyber criminals are taking advantage of the ongoing coronavirus crisis to trick users into downloading malware onto their devices.

In a statement on Twitter, Microsoft Security Intelligence said that hackers are posing as the “Usa Volunteer Organization” and the “Usa Humanitarian Group” and are sending out hundreds of emails offering free COVID-19 medical advice and testing.

Each email aims to install the Trickbot malware using “unique macro-laced” document attachments.

“Like in recent Trickbot campaigns, if allowed to run, the macro uses CHOICE.EXE to wait 20 seconds before downloading the info-stealing payload,” explained Microsoft’s Security Intelligence team. “Trickbot campaigns are known to delay malicious activities to evade emulation or sandbox analysis.”

The company also warned that new phishing campaigns are using the theme of remote working in an attempt to encourage victims to share personal data, such as bank details, over the phone.

“To further avoid raising a flag, phishers don’t put malicious URLs in emails. Instead, they leverage legitimate web services or use attachments that contain the link to the phishing site. In this example, phishers left the email body empty; message & link are in the attached PDF,” Microsoft explained over Twitter.

According to Microsoft 365 Security corporate VP Rob Lefferts, “the trendy and pervasive Trickbot and Emotet malware families are very active and rebranding their lures to take advantage of the outbreak”. 

“We have observed 76 threat variants to date globally using COVID-19 themed lures,” he wrote in a blog post.

Related Resource

2020 report: The threat posed by shadow IoT devices

Unsanctioned IoT devices open a portal for chaos across the network

Download now

Last year, the TrickBot trojan was named the most dangerous threat to healthcare, and it seems to be holding onto that title during the ongoing coronavirus pandemic.

Microsoft’s warning comes weeks after US and UK cybersecurity officials issued a joint warning that hackers, some of them potentially state-backed, are using the disruption caused by the coronavirus pandemic to exploit businesses and the wider public.

Google has also issued a warning to users working from home during the lockdown about a rise in the number of coronavirus-based phishing attacks, many of which are being sent as emails. 

Featured Resources

How to scale your organisation in the cloud

How to overcome common scaling challenges and choose the right scalable cloud service

Download now

The people factor: A critical ingredient for intelligent communications

How to improve communication within your business

Download now

Future of video conferencing

Optimising video conferencing features to achieve business goals

Download now

Improving cyber security for remote working

13 recommendations for security from any location

Download now

Recommended

Apple opens all US stores for the first time in a year
business transformation

Apple opens all US stores for the first time in a year

2 Mar 2021
Cyber security firm saw attacks rise by 20% during 2020
cyber security

Cyber security firm saw attacks rise by 20% during 2020

23 Feb 2021
New York AG sues Amazon over handling of COVID-19
Business strategy

New York AG sues Amazon over handling of COVID-19

17 Feb 2021
How can the cloud industry adapt to a post-COVID world?
cloud computing

How can the cloud industry adapt to a post-COVID world?

16 Feb 2021

Most Popular

Star Alliance passenger data stolen in SITA data breach
data breaches

Star Alliance passenger data stolen in SITA data breach

5 Mar 2021
I went shopping at Amazon’s till-less supermarket so that you don’t have to
automation

I went shopping at Amazon’s till-less supermarket so that you don’t have to

5 Mar 2021
How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

26 Feb 2021