COVID-19: Malware And Phishing Attacks By Threat Actors
ID: e7e9b0f0-5586-5f36-8419-6a388ebe55c2
STIX ID: report--e7e9b0f0-5586-5f36-8419-6a388ebe55c2
Feed Name: Cyble Blog
This Cyble report summarizes analysis of multiple COVID-19–themed malicious campaigns: a Windows 'Covid-21' sample that drops helpers, disables defenses, overwrites the MBR and forces crashes; malicious PDFs and LNK shortcuts that redirect to payload-hosting domains (mshta-based execution); macro-enabled Word documents that decode and run PowerShell to fetch Emotet-related payloads; and adware-distributing APKs. The report includes static/dynamic observations, TTPs, numerous SHA-256 IOCs, and defensive recommendations for detection and hardening.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
