Microsoft Warns of COVID-19 Email Malware Scam
Microsoft and Sophos have warned users to watch out for emails which claim to offer statistics about the COVID-19 pandemic. They actually harbor a combination of malware and legitimate tools that could easily be abused by a hacker.
The emails in question have subject lines such as "Covid-19: [May 22] horrible Charts", claim to come from legitimate sources such as John Hopkins University, and have an attachment that's billed as a spreadsheet file with statistics about deaths and infections. (Source: twitter.com)
Malicious Macro
The attachment does indeed have an Excel file, but the problem is that it includes macros. These are a set of instructions for the computer to carry out a series of steps in a row. This can be a great time-saver in office software when used correctly, but can also automate malicious activity.
In this case the macro tells the computer to download and install a range of files, many of them malicious. Perhaps surprisingly they also include components of the entirely legitimate NetSupport Manager.
This lets somebody remotely access a computer. That's great when it's a technical expert helping a customer (or an ordinary user helping a friend or relative). It's no so great when it's a hacker looking to damage a computer, hunt for sensitive data, or simply use their access to make tech support scams more credible.
Remote Access Tool Disguised
One sign there's something amiss is that the components of NetSupport Manager are installed under the filename dwm.exe. Security company Sophos explains that's done so that if it shows up as a running process in Task Manager, it's likely to be confused with Desktop Window Manager. (Source: sophos.com)
The idea is that it's very credible that Desktop Window Manager would be running at any randomly chosen time, whereas users might be surprised to see remote access software running without them having authorized it.
Sophos notes that as well as the usual advice of not opening attachments on unsolicited emails, users should be very wary about enabling macros in an Office file. In particular, they should ignore any claim that doing so is necessary to display a file correctly.
It's also worth thinking about the wording of the scam email subject line. A legitimate or authoritative source would be unlikely to describe official statistics as "horrible" no matter how human that reaction might be.
What's Your Opinion?
Have you seen such an email? Have you ever dropped your security defences because of an emotional topic? Would it be worthwhile for email applications to warn users whenever they try to open an attachment?
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.