As part of the distance learning implemented in many countries since the outbreak of the COVID-19, governments are distributing the necessary equipment to students. The United Kingdom is among them. However, some of the laptops distributed by the United Kingdom's Department for Education (DfE) to students have been found to be "infected" with malware, as reported by the BBC.

The devices are being distributed free of charge by the government to support students who cannot access remote learning during the pandemic, including children and young people who do not have digital devices, only have smartphones , or share a single device with other members of their family.
The DfE has also worked with mobile network providers to give students access to free dataso they can attend remote lessons.

Bradford Schools teachers have reported that some of the files found on government-issued Windows laptops were infected with malware, discovered while preparing the devices for delivery to students
The UK government has already delivered over 800,000 laptops and tablets so far to schools, academic institutions and local authorities across the country. A Ministry official said: “We are aware of an issue with a small number of devices and our priority is to resolve the issue as soon as possible. The Ministry’s IT teams are in contact with those who have reported this issue. We believe the security incident is not widespread.”

The malware found on the infected laptops is Gamarue (also known as Andromeda). It is a modular malware strain known to be commonly used by Russia and other Eastern European countries. Gamarue is sold on hacking forums and allows attackers to control compromised devices using a Teamviewer plugin. It also has support for keylogger, rootkit, Socks4/5 proxy server and formgrabber plugins that allow it to monitor keystrokes, achieve persistence and steal browser input data.
It can also modify computer settings, steal user information and documents. Computers are usually infected with Gamarue through previous infections, through exploit kits when browsing compromised sites, and through malicious email attachments.

As BleepingComputer reports, some variants of Gamarue have worm capabilities that allow the malware to spread to other devices via infected removable devices, such as portable hard drives and USBs.
In 2011, when samples of this malware were first discovered, Gamarue was primarily used to deliver several malware, including the ransomware , the Kasidet malware (also known as the Neutrino bot) used for DDoS attacks, the Lethic spam bot, and the Ursnif, Carberp, and Fareit info-stealers.
Although Microsoft took down the Andromeda botnet by taking down its servers in a coordinated global operation with law enforcement and other partners in 2017, the malware continues to infect devices on a daily basis to this day.
