Last week in security news, coronavirus-themed spam campaigns delivering Emotet topped a monthly “most wanted” malware list. Security researchers came across the first “living” computer virus they’ve seen in years. Others in the security community spotted a couple of clever new phishing campaigns. Finally, digital criminals swapped out roses for two dozen malicious dating apps this Valentine’s Day season.

Top Story of the Week: Coronavirus Theme in Spam Campaigns Delivering Emotet

Check Point revealed that Emotet nabbed the top spot on its “most wanted” malware list in January 2020. It did so partly by taking advantage of users’ interest surrounding the global coronavirus outbreak.

According to Check Point, the most popular coronavirus-themed Emotet campaign targeted Japanese users in January 2020. This campaign used the coronavirus threat as a lure to scare victims into opening malicious email attachments, noted IBM X-Force in early February. Those attachments were Microsoft Office documents that used malicious macros to infect recipients with Emotet.

Source: iStock

Also in Security News

  • PayPal Phishers Used Scam to Try to Steal All of a User’s Data: SANS’ Internet Storm Center came across a scam that used a malicious site to trick users into providing their PayPal credentials. Once it obtained those details, the scam tried to convince users to hand over their address, payment card data, Social Security number, birth data and other sensitive information.
  • First Computer Virus in Years Spotted by Researchers: The team at Kaspersky Lab observed KBOT malware injecting malicious code into Windows executable code as a means of distribution. This technique made the malware — which tried to deploy web injects in order to steal users’ personal and banking data — the first true “living” computer virus detected by the security firm in years.
  • Over 20 Malicious Apps Masquerading as Popular Dating Apps: Leading up to Valentine’s Day, Kaspersky Lab analyzed malware abusing the names of over 20 well-known dating applications. This analysis led the researchers to uncover 1,963 malicious files that masqueraded as Tinder and Badoo in order to prey upon users.
  • Ransomware Infection Disclosed by Florida City Police Department: In early February, the police department for the municipality of North Miami Beach, Florida, revealed that its IT personnel had discovered a ransomware infection. Officials at the police department notified the FBI, the U.S. Secret Service and the Miami-Dade Police Department upon discovering the attack.
  • Vulnerable Driver Abused by Robbinhood Ransomware to Delete Security Tools: Researchers at Sophos witnessed samples of the Robbinhood ransomware abusing CVE-2018-19320 in a signed Gigabyte driver in order to temporarily disable driver signature enforcement in Windows. This tactic allowed the ransomware to load its unsigned driver and use it to kill security processes.
  • Clever Phishing Campaign Delivered Fake Emails From Amex, Chase: According to Bleeping Computer, MalwareHunterTeam discovered a spam campaign sending out fake emails from Amex and Chase. The emails asked users to approve suspicious charges; when they clicked on a button, the scam attempted to trick them into supplying their personal and financial data.
  • Supply Chain Software Firms Warned to Beware of Kwampirs Malware: The FBI warned supply chain software firms to be on the lookout for a Kwampirs malware infection. The law enforcement agency revealed that the remote-access Trojan (RAT) was specifically targeting organizations in the industrial, financial, energy and healthcare sectors.

Security Tip of the Week: Bolster Your Organization’s Anti-Phishing Defenses

Security professionals can help bolster their organizations’ anti-phishing defenses by conducting simulated phishing attacks and using the results of these exercises to improve their workforce’s preparedness against phishing campaigns. Additionally, infosec personnel should develop incident response processes for investigating phishing and business email compromise (BEC) attacks.

More from

The importance of Infrastructure as Code (IaC) when Securing cloud environments

4 min read - According to the 2023 Thales Data Threat Report, 55% of organizations experiencing a data breach have reported “human error” as the primary cause. This is further compounded by organizations now facing attacks from increasingly sophisticated cyber criminals with a wide range of automated tools. As organizations move more of their operations to the cloud, they must also become increasingly aware of the security risks and threats that come with it. It’s not enough anymore to simply have a set of…

Data never dies: The immortal battle of data privacy

4 min read - More than two hundred years ago, Benjamin Franklin said there is nothing certain but death and taxes. If Franklin were alive today, he would add one more certainty to his list: your digital profile. Between the data compiled and stored by employers, private businesses, government agencies and social media sites, the personal information of nearly every single individual is anywhere and everywhere. When someone dies, that data becomes the responsibility of the estate; but what happens to the privacy rights…

Vulnerability resolution enhanced by integrations

2 min read - Why speed is of the essence in today's cybersecurity landscape? How are you quickly achieving vulnerability resolution? Identifying vulnerabilities should be part of the daily process within an organization. It's an important piece of maintaining an organization’s security posture. However, the complicated nature of modern technologies — and the pace of change — often make vulnerability management a challenging task. In the past, many organizations had to support manual integration work to get different security systems to ‘talk’ to each…

How I got started: SIEM engineer

3 min read - As careers in cybersecurity become increasingly more specialized, Security Information and Event Management (SIEM) engineers are playing a more prominent role. These professionals are like forensic specialists but are also on the front lines protecting sensitive information from the relentless onslaught of cyber threats. SIEM engineers meticulously monitor, analyze and manage security events and incidents within an organization. They leverage SIEM tools to aggregate and correlate data, enabling them to detect anomalies, identify potential threats and respond swiftly to security…