evrohachik / covid19_cyber_threats

Compilation of the cyber_threats around covid-19

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Overview - Cyber Threats Abusing COVID-19

This page is a best effort attempt to follow the cyber threats that are now showing up in relationship with Covid 19.

Real-time updates by CERT-EU : https://media.cert.europa.eu/cert/filteredition/en/Cybersecurity-Covid-19.html

Phishing

Many emails themed with COVID-19 are sending office documents with malicious attachments or links to dropper sites (trickbot, hancitor, others). Moreover there are many sites with urls design to lure users interested in covid-19 to malicious sites to drop desktop/mobile malware.

Covid-19 map copycat or fake tracking apps

Many versions of malware pretending to be the official map were found in the wild.

Cyber attacks

Currently there are a series of DDOS hitting critical infra (mirai like + others) as well as targeted attacks against healthcare institutions

Magecart alert

Due to the fact that most people are buying online because of social distancing card skimmers risk is very high. Megacart actors are experts when it comes to inject their code on 3rd parties webshops so people can be greatly affected by this threat. Increase of 20% of magecart activity has been confirmed

Peace offering by big threat actor names.

Maze, DoppelPaymer, Ryuk, Sodinokibi/REvil, PwndLocker, and Ako have informed that they wont target healthcare institution while the covid-19 crisis. However it doesn't mean that they are not getting access to their networks. There is a big chance that as soon as the crisis is over many hospital will be affected since currently cybersecurity is not a priority to them.

And its gone:

Working from home (WFH) Risks

As people work from home there is the risk of infection been unnoticed. Normally your workstation is inside your company network, now it is not and most likely you are using the ISP's DNS rather than the company one normally used and monitored by SoC, so if you get infected now it is harder to notice until is too late. Moreover to have more flexibility companies are allowing people to use their home computers to access company resources via VPN. This systems could have been already compromise and are not hardened. Lastly many many campaigns have mutated towards a covid-19 theme but this doesn't mean that normal cyber threats have stopped. So no malware campaigns shall be neglected in either case covid-19 or not covid-19 themed.

Other Threats regarding covid-19

COVID-19 malware samples

Advisory to avoid covid-19 cyber threats

Phishing in the Time of COVID-19: How to Recognize Malicious Coronavirus Phishing Scams: https://www.eff.org/deeplinks/2020/03/phishing-time-covid-19-how-recognize-malicious-coronavirus-phishing-scams

COVID-19 IOCs

About

Compilation of the cyber_threats around covid-19