Check Point Research noted a spike in domain registrations with the word coronavirus earlier this month as hackers increase malicious activity surrounding the disease.
Check Point cited “vaccinecovid-19\.com” as an example of a malicious domain. It was created on February 11, 2020, registered in Russia, and offers a $300 treatment for the coronavirus.

Hackers are also exploiting virus fears as a new way to distribute the Emotet trojan.
Check Point's monthly malware report found that the top three malware families in January are the same as December: Emotet maintains the top spot, affecting 13% of organizations worldwide, followed by XMRig and Trickbot with 10% and 7% respectively.
Emotet was originally a banking Trojan, but has recently been used to distribute other malware or malicious campaigns. It can also be spread through spam emails containing malicious attachments or links.
The January report also identified a malicious sample called Lokibot targeting Indonesia with a coronavirus message. Check Point expects spam campaigns to increase in the coming days.

Check Point recommended that IT departments share these tips with users:
- Do not click on advertising links in emails.
- Watch out for “special” offers, such as 80% off a new iPhone or an exclusive treatment or cure for the coronavirus.
- Be careful about domains, misspellings in emails or websites, and unknown email senders.
David Richarson, vice president of product management at Lookout, said people should also be wary of emails that try to create a sense of urgency to take advantage of a deal.
Richardson said the training should include tips on identifying a phishing site, including URLs that look suspicious.
