sb-nz logo
Story image

Reports suggest spike in vaccine-related phishing campaigns

12 Aug 2020

When the COVID-19 pandemic picked up steam in its initial spread across the world in March, instances of pandemic-related phishing campaigns were rife across the internet. 

Thousands of email attacks and scams cropped up, and many more fell victim to them. Much of their success can be attributed to their exploitation of people’s fears around COVID-19 – many campaigns spoke of virus hotspots, or posed as government health departments to seem credible.

Now, with several months between the first reports of the virus, many phishing campaigns have changed course – instead of stoking fear, and with dozens of efforts to develop vaccines entering their final stages around the world, they are exploiting hopes for such a vaccine.

According to new research from Check Point, the primary attack delivery method is email, constituting 82% of all attack vectors for malicious files in the last month.

In these campaigns, attackers send emails with subject lines that include deceptive vaccine-related content, which inevitably conceal malicious links in the body. These links lead to a malicious file usually in the form of .exe, .xls or .doc. 

“Lately, we’re seeing a clear trend adopted by hackers:  deceive the masses by using their interest in coronavirus vaccines. Most of the campaigns involve a person’s inbox, which is concerning,” says Check Point data manager Omer Dembinsky.

“Over 80% of attacks against organisations start from a malicious email. Email is the first link in a chain of attacks. 

“Since email attacks usually involve the human factor, employees’ email inboxes are an organisation’s weakest link.”

Here are some examples included in Check Point’s research.

Subject: Urgent Information Letter: Covid-19 New Approved Vaccines

This campaign is an example of malspam, and contained malicious .EXE files with the name ‘Download_Covid 19 New approved vaccines.23.07.2020.exe’.

When a victim clicked, an InfoStealer was installed which made light work of extensive data theft, including login information, usernames and passwords from the user’s computer.

Subject: UK coronavirus vaccine effort is progressing

In this example, the phishing campaign contained a malicious link within an email - the subject line of which read 'UK coronavirus vaccine effort is progressing badly appropriate, recruiting consequence and elder adults'.

Further investigation revealed that it was used to redirect traffic to a known medical phishing website, which was trying to imitate a legitimate Canadian pharmacy.

Pandemic-related attacks are dropping

Despite overall numbers of cyber-attacks remained high in July, since its zenith in March and April, the number of COVID-19-related attacks has dropped significantly, according to Check Point researchers.

In July, there were 61,000 coronavirus-related attacks, a decrease of over 50% when compared to the weekly average of 130,000 attacks in June.

“Closing this security gap requires protections against various threat vectors: phishing, malware, data theft and account-takeover,” continues Dembinsky.

“I strongly urge everyone to closely read the subject lines of emails coming in. If it has the word “vaccine” in it, think twice. 

“Chances are that you are the threshold of being tricked into giving up your most sensitive, most private information.”

Story image
Trend Micro receives AWS Outposts Ready designation
rend Micro solutions are now fully and demonstrably capable of integrating with Outposts deployments.More
Story image
Kaspersky finds red tape biggest barrier against cybersecurity initiatives
The most common obstacles that inhibit or delay the implementation of industrial cybersecurity projects include the inability to stop production (34%), and bureaucratic steps, such as a lengthy approval process (31%) and having too many decision-makers (23%). More
Story image
Jamf extends Microsoft collaboration with iOS Device Compliance
Organisations will soon be able to use Jamf for Apple ecosystem management while using Azure Active Directory and Microsoft Endpoint manager to maintain conditional access.More
Story image
ESET launches the latest version of its Mobile Security solution
“With this latest version of ESET Mobile Security, we want to ensure our users feel completely secure when performing financial transactions on their devices, in addition to being protected from malware and phishing attempts."More
Story image
Remote staff overestimating knowledge of cybersecurity basics
‘Unconscious incompetence’ is one of the most difficult issues to identify and solve with security awareness training.More
Story image
The SASE triangle: How a CASB protects managed apps
Enterprises that fail to adapt to the modern business world when it comes to security are likely to fall prey to data breaches and experience a host of other problems, writes Bitglass product marketing manager Will Houcheime.More