Connect with us

Hi, what are you looking for?

HEADLINES

SophosLabs tracks significant uptick in COVID-19 cyber-scams

The volume of “COVID-19” and “coronavirus” email scams have nearly tripled in the past week.

SophosLabs is tracking how the use of “COVID-19” and “coronavirus” in domain names, spam, phishing attacks, and malware has skyrocketed in a new Uncut blog, “Facing down the myriad threats tied to COVID-19.” This article is a “live report” that SophosLabs Uncut will update as findings unfold.

Specifically, the article shows that the volume of “COVID-19” and “coronavirus” email scams have nearly tripled in the past week – see the below chart. 

Attackers are also increasingly impersonating the World Health Organization (WHO), Centers for Disease Control and Prevention (CDC), North America, and the United Nations (UN), as evidenced in scams tracked by SophosLabs. Attached are a few new examples.

“Cybercriminals are wasting no time in shifting their dirty, tried and true attack campaigns toward advantageous lures that prey on mounting virus fears. It’s easy to see, for example, that the attackers behind a new Chloroquine scam (attached) are the same as those behind a recent herbal Viagra scam,” according to Sophos Principal Research Scientist Chester Wisniewski.  

“With global spam volumes estimated to be in the hundreds of billions, for 2-3% of those to be COVID-19 themed is significant. Similar to A/B testing of advertisements and web pages, criminals often dip a toe in the water when there is a new or sensational topic in the news. If the new topic proves a more effective lure than the previous scam bait they begin switching to new lures.

“In fact in one of the spam campaigns we tracked this week, there was evidence of exactly that. These particular criminals had been using fake shipping and delivery emails to convince unsuspecting victims into opening attachments and infecting their computers with the Kryptik Trojan. Now the main body of the email pretends to come from erecruit@who.int with “health advice” in the attachment, but when we carefully inspect the plain text body, we see it matches a previous spam campaign from this same criminal using a lure pretending to be about invoices and deliveries.

Advertisement. Scroll to continue reading.

“The increases we are seeing are likely due to two important factors. First, as time passes more and more criminal groups are joining the party on using all this interest in COVID-19 to steal money from people. Secondly, it takes time. Any given criminal group has to handcraft the spams to convince the recipient to take an action. In the research community we call this the call to action. The call to action might be to open the attachment, visit the website or, in the case of the WHO Bitcoin scam (attached), to donate cryptocurrencies to criminal controlled Bitcoin wallets. Crafting these messages takes time, especially for those who are not native English speakers.

“Even the most innocuous mention of something by a politician or a celebrity can lend a scam credibility or present a new business opportunity. Two recent examples come to mind. One spam campaign offering to tell you about the government cover up and attempting to sell you a COVID-19 survival guide used celebrity Gwyneth Paltrow as a lure in its subject line. A tipoff the email is a fake is the incorrect spelling of her first name as Gwenith (attached), but this could easily be missed or glossed over. A few days ago President Donald Trump mentioned the possible efficacy of a drug called Chloroquine against Coronavirus immediately leading to WordPress blog comment spammers switching from pitching herbal Viagra to instead attempting to sell you Chloroquine, which can be quite dangerous when not taken under the supervision of a doctor. And within only two days of the WHO creating a charity called the Solidarity Response Fund, criminals were soliciting Bitcoin donations pretending to be the charity, even implying your donation is fully tax deductible in the US or Europe.”

SophosLabs has uncovered a variety of different malicious email campaigns connected to COVID-19, including:

  • Phishing scams impersonating the WHO, CDC, and other healthcare organizations to deliver malware via malicious documents disguised as official information on how to stay safe during the pandemic
  • Cybercriminals impersonating charities and relief organizations like the WHO’s COVID-19 Solidarity Response Fund to trick victims into sending them Bitcoin
  • SophosLabs is updating its Uncut blog with new findings in real time

Sophos News is providing tips and free resources as people navigate the work-from-home tech/security gauntlet:

Naked Security is providing security tips and industry news:

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

Maya has already integrated National ID eVerify, the Philippine Statistics Authority’s identity-verification service, into its onboarding process. Since early this year, eligible customers have been...

HEADLINES

In 2025 alone, Converge denied nearly 12 billion entry requests to websites hosting dangerous, inappropriate, and harmful content that attempted to pass through its...

HEADLINES

The announcement represents one of the first major third-party technology integrations following the launch of Sophos Fusion, demonstrating Sophos' commitment to an open ecosystem...

HEADLINES

APAC consumers are more concerned about digital tech usage for crime than consumers globally (35% vs 32%). The awareness is highest in Thailand (39%),...

HEADLINES

Through this partnership, Sophos intends to give partners a new way to deliver frontier AI security as one connected defense system, and to build...

HEADLINES

“It is the time for Radenta to demonstrate that it is strongly committed to protecting client data,” remarks Nereo Bolante, Co-Director, Radenta Ethics, Compliance, and Governance Team...

HEADLINES

Attackers are operationalizing artificial intelligence (AI) to collapse attack workflows from weeks to days. The report finds that AI’s most immediate impact on cybercrime...

HEADLINES

The prominence of identity attacks in ransomware indicates a shift in method, as attackers increasingly recognize identity as a key component in ransomware delivery....

Advertisement