Hackers are not letting any opportunity pass them by, especially when it comes to government- backed professionals . In recent weeks, state-run hacking groups in China, North Korea, and Russia have been according using the coronavirus to attract the attention of victims, to new data . Then, after tricking them, they infect them with malware or gain access to their infrastructure.
They are not the first hackers to exploit the coronavirus to launch attacks. Security experts have already seen several such attacks and expect many more to be discovered.
Cyberspies seize every opportunity. They never leave such incidents unexploited, because they know that many people will respond. They have used other such incidents in the past, such as the terrorist attack in Paris in November 2015, the oppression of the Uyghur population in China, etc. Tragic events are always the best bait.
RUSSIA
The first state-sponsored hacking group to use the coronavirus for its illegal activities is the Hades group, said to originate from Russia, and linked to the APT28 (Fancy Bear) group, one of the groups that breached the DNC committee in 2016.
According to security firm QiAnXin, the Hades group carried out a campaign in mid-February aimed at spreading a C# backdoor trojan. The hackers hid it inside documents that supposedly contained the latest news about the coronavirus.
The targets of the attack were Ukrainian citizens. The hackers sent phishing emails, which supposedly came from the Center for Public Health of the Ministry of Health of Ukraine.
These emails were part of a broader disinformation campaign that hit the entire country, on different fronts.
At the same time that the Hades hackers were sending out their emails, a wave of coronavirus-related spam emails hit the country. This was followed by a flood of messages on social media claiming that the coronavirus had arrived in the country.
According to a report by BuzzFeed News, the emails and social media posts caused panic and unrest among a large portion of the population.
BuzzFeed reports that in some cities in Ukraine, residents filled hospitals as they feared their children would be infected with the coronavirus.
Amidst this general panic, some emails distributing malware have a much greater chance of going unnoticed and reaching their targets.

NORTH KOREA
The next country to use the coronavirus for spear-phishing attacks is North Korea. In late February, such an attack took place, however, it was not as sophisticated as the one that hit Ukraine.
According to a tweet from the company IssueMakersLab, a hacking group from North Korea hid malware inside documents that supposedly described North Korea's situation regarding the coronavirus.
The documents, believed to have been sent to South Korean officials, contain BabyShark , a malware previously used by a North Korean hacking group known as Kimsuky .
CHINA
However, the country that has carried out the most malware campaigns coronavirus-related China. Over the past two weeks, Chinese hackers have been particularly active.
Earlier this month, Vietnamese security firm VinCSS detected a Chinese hacking group codenamed Mustang Pandasending emails with a RAR file that “carried a message about the coronavirus” and “originated” from the Vietnamese prime minister. The file essentially infected victims’ computers with a backdoor trojan.
The second attack has now been revealed by Check Point . The company said another Chinese group called Vicious Panda targeted Mongolian government organizations by sending malicious documents related to coronavirus prevention.
As we mentioned above, state-run hacking groups are not the only ones exploiting the coronavirus to carry out malware attacks. Many security have also discovered campaigns by "ordinary" hackers in recent weeks.

