HomeSecurityHackers attack governments and health organizations

Hackers attack governments and health organizations

Hackers

The pandemic continues to be used by hackers to carry out malware, phishing email, scams , and spread misinformation.  

Security researchers have discovered a large number of COVID-19, which primarily targeted governments and health organizations.

Security researchers from Unit 42 noticed that many malicious emails appear to come from the WHO with a spoofed address (noreply@who[.]int).

The campaign targets individuals affiliated with a Canadian government health organization actively working to mitigate COVID-19.

The binary it secretly downloads has an Adobe Acrobat icon. Once executed, it sends an HTTP GET request to download the image, which is used as a ransomware.

Once the image is downloaded, then a request will be created based on the victim's username and hostname.

The ransomware encrypts the following files and adds the .locked20 extension:

“.abw”, “.aww”, “.chm”, “.dbx”, “.djvu”, “.doc”, “.docm”, “.docx”, “.dot”, “.dotm”, “.dotx”, “.epub”, “.gp4”, “.ind”, “.indd”, “.key”, “.keynote”, “.mht”, “.mpp”, “.odf”, “.ods”, “.odt”, “.ott”, “.oxps”, “.pages”, “.pdf”, “.pmd”, “.pot”, “.potx”, “.pps”, “.ppsx”, “.ppt”, “.pptm”, “.pptx”, “.prn”, “.prproj”, “.ps”, “.pub”, “.pwi”, “.rtf”, “.sdd”, “.sdw”, “.shs”, “.snp”, “.sxw”, “.tpl”, “.vsd”, “.wpd”, “.wps”, “.wri”, “.xps”, “.bak”, “.bbb”, “.bkf”, “.bkp”, “.dbk”, “.gho”, “.iso”, “.json”, “.mdbackup”, “.nba”, “.nbf”, “.nco”, “.nrg”, “.old”, “.rar”, “.sbf”, “.sbu”, “.spb”, “.spba”, “.tib”, “.wbcat”, “.zip”, “7z”, “.dll”, “.dbf”

According to researchers, the ransomware variant being used is EDA2.

Another phishing email campaign targeted individuals who worked in the healthcare sector and in pharmaceutical and government industries.

The emails contain attachments containing the AgentTesla malware, which has been active since 2014.

It is capable of stealing credentials that are stored in a large list of web browsers, FTP clients, File Downloaders, etc.

The malicious software AgentTesla, is sold on various forums and is the top choice of the malicious actor SilverTerrier.

As more and more people are forced to work from home, their online security has been compromised. And the attacks carried out by hackers are making things even worse. For this reason, users should be more careful with the emails they receive and not open links that seem dangerous.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS