The World Health Organization (WHO) is warning people around the world about a new phishing campaign that is using the coronavirus to attract victims' attention. According to the organization, attackers are sending phishing emails claiming to be from the WHO. The goal is to steal information and money victims' install malware on devices .
“ Criminals are impersonating the WHO to steal money or sensitive information,” says the United Nations agency on coronavirus fraud.

The WHO has become aware of phishing emails that attempt to take advantage of the critical situation prevailing with the coronavirus.
Phishing emails are sent by people who pretend to be from an organization and ask victims to provide personal information, such as usernames and passwords .This information is usually sent to fake sites, which are taken via links in the email. Attackers may also ask victims to open malicious attachments that contain malicious payloads.
How to protect yourself from the phishing campaign ?
“If you are contacted by an individual or organization that appears to be from the WHO, check its authenticity before responding,” the WHO says.
How is this done?
- Check the email address– WHO addresses use the format person@who.int.
- Check the links contained in the email. Do not open the link directly. Check it in browser .
- Never give your personal information to third parties.
- Don't panic. Think before you do anything. Attackers aim to stress you out and make you act immediately, without thinking.
- If you provide sensitive information, don't panic. Change credentials your
- If you become aware of a scam, please report the incident at https://www.who.int/about/report_scam/en/.
Hackers always find ways to exploit emergencies. The WHO declared in late January that the situation with the new coronavirus was critical.
Phishing campaigns
Earlier this month, the Sophos security team discovered phishing emails from this campaign, which supposedly contained attached documents regarding coronavirus measures safety
The attackers asked victims to download the attachment to computer by clicking a button that said “Security Measures.” This “click” led them to a phishing page.
This page appeared as the official WHO site. A pop-up appeared in front of it asking for email.
When users entered their username and password and clicked the “Verify” button, their credentials were sent to a server controlled by the attackers.

There have been a number of hacking and phishing attacks exploiting the coronavirus over the past two months. In late January, a campaign used the topic to spread the Emotet malware.
Other researchers discovered attacks using Remote Access Trojan (RAT), Trojan, stealer/keylogger and wiper.
Finally, the coronavirus has been used to carry out disinformation campaigns.
