Spearphishing Campaign Exploits COVID-19 To Spread Lokibot Infostealer

By Anthony Berrios


Blog Post #15

Yet another corona-virus inspired attack has been discovered recently, this time a phishing attack. This attack was spreading a Lokibot trojan. It was a newly created spearphishing email that was COVID-19 themed and made to look like it was coming from WHO, the World Health Organization. The cyber criminals even managed to use the WHO trademark in their emails scam to make the emails look more authentic.

The attack was first found at FortiGuard Labs on March 27th. The email scam was said to claim to be from WHO and attempts to misinform readers related to the pandemic to convince users it’s legitimate. Instead it sends an attachment that unleashes the infostealer LokiBot if downloaded and executed, according to a blog post published Thursday by threat analyst Val Saengphailbul.

Val then goes and points out how much of the COVID-19 information in the email has real characteristics, however it was apparent from the grammar of the email that English was not the scammers first language.

This is just another example of internet scams that are taking full advantage of the COVID-19 pandemic. This article is interesting because of its significance and relevance to the pandemic that we are all currently facing. This article and many of the others recently on my blog that refer to the corona-virus pandemic should be a reminder to be careful on the internet even more so now than ever.

CLICKABLE SOURCE!

Leave a comment

Design a site like this with WordPress.com
Get started