A new phishing campaign is luring unsuspecting victims by claiming to provide detailed information via emails regarding the health of US President Donald Trump, who announced a few days ago that he was infected with COVID-19.
With the upcoming US election being a bipartisan one, people on different sides of the aisle are obsessed with Trump's health for various reasons. To capitalize on this, the hackers behind the BazarLoader trojan have launched a new phishing campaign claiming to provide confidential information about Trump's condition.

The new phishing campaign detected by researchers at cybersecurity ProofPoint uses several different email subjects. Some of them are as follows:
- Recent material regarding the President's illness
- Recent information on the President's condition
- Recent information regarding the President's illness
As BleepingComputer reports, the spam emails claim to have new information about Trump's health, but ask unsuspecting victims to download a document using a link embedded in it.

When a recipient clicks on the link, they will be taken to a Google Doc that states that Google has scanned the file and it is safe. It then asks the visitor to download the document. When someone clicks on the download link, instead of downloading a Word document, a BazarLoader executable will be downloaded. BazarLoader is a backdoor trojan that appears to have been created by the TrickBot gang . Once installed, BazarLoader allows hackers to gain remote access to the victim’s computer and use it to compromise the rest of the network. These attacks eventually lead to the deployment of Ryuk ransomware on a victim’s network, which turns a computer breach into a corporate attack

BazarLoader isn't the only malware exploiting the upcoming US elections and Trump. Last week, ProofPoint detected emails purporting to come from the Democratic National Convention (DNC), infecting recipients with the Emotet trojan.
