
FireEye believes that the APT32 hacking group , also known as Ocean Lotus , was involved in a spear-campaign targeting the Wuhan government and the Chinese Ministry of Emergency Management phishing . The goal is to spy on and obtain information related to the COVID-19 pandemic that has affected the entire planet. Ocean Lotus is said to be linked to the Vietnamese government.
FireEye said the COVID-19 espionage began on January 6, when a phishing email was sent to the Chinese Ministry of Emergency Management, containing a link. That link alerted the hacking group to open the email . Examining the URLs, FireEye said the group was also trying to spy on the Wuhan government
The domains in the embedded links were the same as those used in December in another phishing campaign in Southeast Asia, called Metaljack.
“APT32 likely used malicious attachments themed around COVID-19,” FireEye said.

"We have not revealed the full execution chain, but we have discovered a Metaljack loader that displays, at the start of its payload, a document titled COVID-19 in Chinese."
The shellcode payload collects system information and appends it to URL strings. It then loads Metaljack into memory.
According to FireEye, the crisis that has arisen from COVID-19 is creating a strong concern for governments and there is an atmosphere of distrust that encourages the collection of information in such ways.
"Until this crisis is over, we expect espionage cyber to continue to intensify globally."
APT32 has previously been linked to attacks on Toyota Australia and Toyota Japan . It was also accused of breaches of BMW and Hyundai networks in late 2019 .
Palo Alto Networks said it has discovered more than 116,000 coronavirus -related domain names since the beginning of the year through March 31. Of those, 2,000 were classified as malicious and more than 40,000 as high-risk .
The company said that the "malicious" designation was placed on all domains involved in command and control, phishing, and malware distribution. The high-risk domains were mainly scam pages and coin miners.
"People should be particularly cautious of emails and new sites related to COVID-19, whether they claim to have information about the virus or a cure," the company said.
