Microsoft warns of "prolific" Trickbot malware exploiting COVID-19 crisis
Hackers are sending out hundreds of emails offering free advice and testing


Microsoft has warned that cyber criminals are taking advantage of the ongoing coronavirus crisis to trick users into downloading malware onto their devices.
In a statement on Twitter, Microsoft Security Intelligence said that hackers are posing as the “Usa Volunteer Organization” and the “Usa Humanitarian Group” and are sending out hundreds of emails offering free COVID-19 medical advice and testing.
Each email aims to install the Trickbot malware using “unique macro-laced” document attachments.
WHO doubles its security team as phishing attacks ramp up 46% of small and medium businesses targeted by ransomware and 73% paid NCSC removes over 2,000 online coronavirus scams German government loses 'tens of millions' in COVID-19 phishing attack Hackers advertise critical Zoom Windows bug for $500,000
“Like in recent Trickbot campaigns, if allowed to run, the macro uses CHOICE.EXE to wait 20 seconds before downloading the info-stealing payload,” explained Microsoft’s Security Intelligence team. “Trickbot campaigns are known to delay malicious activities to evade emulation or sandbox analysis.”
The company also warned that new phishing campaigns are using the theme of remote working in an attempt to encourage victims to share personal data, such as bank details, over the phone.
“To further avoid raising a flag, phishers don’t put malicious URLs in emails. Instead, they leverage legitimate web services or use attachments that contain the link to the phishing site. In this example, phishers left the email body empty; message & link are in the attached PDF,” Microsoft explained over Twitter.
According to Microsoft 365 Security corporate VP Rob Lefferts, “the trendy and pervasive Trickbot and Emotet malware families are very active and rebranding their lures to take advantage of the outbreak”.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
“We have observed 76 threat variants to date globally using COVID-19 themed lures,” he wrote in a blog post.
RELATED RESOURCE
2020 report: The threat posed by shadow IoT devices
Unsanctioned IoT devices open a portal for chaos across the network
Last year, the TrickBot trojan was named the most dangerous threat to healthcare, and it seems to be holding onto that title during the ongoing coronavirus pandemic.
Microsoft’s warning comes weeks after US and UK cybersecurity officials issued a joint warning that hackers, some of them potentially state-backed, are using the disruption caused by the coronavirus pandemic to exploit businesses and the wider public.
Google has also issued a warning to users working from home during the lockdown about a rise in the number of coronavirus-based phishing attacks, many of which are being sent as emails.
Having only graduated from City University in 2019, Sabina has already demonstrated her abilities as a keen writer and effective journalist. Currently a content writer for Drapers, Sabina spent a number of years writing for ITPro, specialising in networking and telecommunications, as well as charting the efforts of technology companies to improve their inclusion and diversity strategies, a topic close to her heart.
Sabina has also held a number of editorial roles at Harper's Bazaar, Cube Collective, and HighClouds.
-
AI is helping bad bots take over the internet
News Automated bot traffic has surpassed human activity for the first time in a decade, according to Imperva
By Bobby Hellard
-
Two years on from its Series B round, Hack the Box is targeting further growth
News Hack the Box has grown significantly in the last two years, and it shows no signs of slowing down
By Ross Kelly
-
Phishing emails target victims with fake vaccine passport offer
News Scammers could steal victims’ personal information and never deliver the illegal goods, Fortinet warns
By Rene Millman
-
COVID-related phishing fuels a 15-fold increase in NCSC takedowns
News The NCSC recorded a significant jump in the number of attacks using NHS branding to lure victims
By Bobby Hellard
-
COVID vaccine passports will fail unless government wins public trust, ICO warns
News Data watchdog's chief Elizabeth Denham warns that it’s not good enough to claim ‘this is important, so trust us’
By Keumars Afifi-Sabet
-
Fake COVID vaccination certificates available on the dark web
News Fast-growing market emerges for people wanting quick vaccine proof to travel abroad
By Rene Millman
-
Cyber security firm saw attacks rise by 20% during 2020
News Trend Micro found attackers also heavily targeted VPNs
By Danny Bradbury
-
Hackers using COVID vaccine as a lure to spread malware
News Cyber criminals are impersonating WHO, DHL, and vaccine manufacturers in phishing campaigns
By Rene Millman
-
Website problems slow coronavirus vaccine rollout
News Florida is the epicenter of website issues, as patients struggle with malfunctioning sites and hackers
By Danny Bradbury
-
NHS COVID-19 app failed to ask users to self-isolate due to 'software glitch'
News The bug is the latest in a long line of errors and glitches to plague the government's contact-tracing app
By Keumars Afifi-Sabet