Security researchers at FortiGuard Labs have discovered a new campaign that is exploiting the COVID-19 outbreak by sending emails purporting to come from the World Health Organization (WHO) to spread a malware, the LokiBot trojan. The COVID-19-themed malware campaign was uncovered on March 27, when researchers discovered emails purporting to come from the WHO to announce ways to combat misinformation related to the COVID-19 outbreak. The emails use an attachment titled “COVID_19- WORLD ORGANIZATION HEALTH CDC_DOC.zip.arj,” which spreads the LokiBot trojan.

FortiGuard Labs recently discovered a new COVID-19-themed email sent from [159.69.16 [.] 177], which uses the World Health Organization trademark in an attempt to convince recipients of its authenticity. The email has the subject line “Coronavirus Disease (COVID-19) Important Announcement [.] . It also includes an attachment titled “COVID_19- WORLD ORGANIZATION HEALTH CDC_DOC.zip.arj” that appears to contain additional information, but is actually a trap for recipients to download the malware. In addition, the email contains information about the pandemic along with suggestions and coping tips. It is written in English, but researchers believe that the hackers behind this campaign are not English speakers, considering the spelling, grammar, and punctuation they use. The message is purported to come from a WHO Center for Disease Control. It appears that the hackers are associating the WHO with the US Centers for Disease Control (CDC), despite the fact that the two organizations are separate. The attachment “COVID_19- WORLD ORGANIZATION HEALTH ORGANIZATION CDC_DOC.zip.arj” is a compressed file in ARJ format, a format likely used to evade detection. By clicking on the attachment and unzipping the file, users will see a “DOC.pdf.exe” extension instead of “Doc.zip.arj,” prompting them to open the file.

Once the file is opened, the LokiBot trojan injection begins. The malware then steals sensitive information, such as various credentials, including FTP credentials, saved passwords , passwords saved in the browser , and more. URL: hxxp: / / bslines [.] Xyz / copy / five / fre.php.
LokiBot has been known since 2015. It is a malware that has been used in many malspam campaigns to steal credentials from browsers, customer emails, management tools, and has also been used to target cryptocurrency holders. The original LokiBot malware was developed and sold via email by a hacker who appears online under the pseudonym “lokistov” (also known as Carter). It was initially advertised on several hacking forums, where it was sold for up to $300, while later other hackers began offering it for under $80 to “underground” cybercriminals.
FortiGuard researchers revealed that users from all over the world have been infected by this particular malware campaign exploiting COVID-19, with the majority of them located in Turkey (29%), Portugal (19%), Germany (12%), Austria (10%), and the US (10%). Infections related to this campaign have also been detected in Belgium, Puerto Rico, Italy, Canada, and Spain.
