Cybercriminals using coronavirus-themed emails to deliver malware: report

Advertisement

Advertise with us

TORONTO - Criminal groups are exploiting fears over the recent novel coronavirus outbreak in an email phishing campaign directed at the global shipping industry, according to a report issued Monday by a California-based cybersecurity firm.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 10/02/2020 (2425 days ago), so information in it may no longer be current.

TORONTO – Criminal groups are exploiting fears over the recent novel coronavirus outbreak in an email phishing campaign directed at the global shipping industry, according to a report issued Monday by a California-based cybersecurity firm.

Proofpoint said the new campaign uses emails with bogus Microsoft Word attachments that are designed to install a type of malware known as AZORult.

AZORult has been around since at least 2016 and can be used to install ransomware, which is designed to lock legitimate users out of their computer systems until a ransom is paid.

A woman uses her computer keyboard to type while surfing the internet in North Vancouver, B.C., on December, 19, 2012. A U.S. cyber security company says criminal groups are exploiting fears over the new coronavirus to attack the global shipping industry.California-based Proofpoint says it has detected a new email campaign that uses Microsoft Word attachments designed to trick recipients into installing a type of malware known as AZORult. THE CANADIAN PRESS/Jonathan Hayward
A woman uses her computer keyboard to type while surfing the internet in North Vancouver, B.C., on December, 19, 2012. A U.S. cyber security company says criminal groups are exploiting fears over the new coronavirus to attack the global shipping industry.California-based Proofpoint says it has detected a new email campaign that uses Microsoft Word attachments designed to trick recipients into installing a type of malware known as AZORult. THE CANADIAN PRESS/Jonathan Hayward

“In these (coronavirus-related) attacks, we don’t see AZORult downloading ransomware currently,” Proofpoint said.

“However, because of AZORult’s configurable nature and past use in conjunction with ransomware that remains a real threat.”

Proofpoint didn’t provide statistics on how many actual coronavirus-themed malicious emails have been detected or how much damage has been caused by coronavirus-themed malicious emails.

The Canadian government’s Centre for Cyber Security said in an email that it was aware of both the AZORult malware and coronavirus-related phishing campaigns but didn’t comment specifically on the Proofpoint report.

“Cyber actors tend to use social engineering and topical subjects to lure their targets to click on a malicious link,” the centre said.

Its website cyber.gc.ca provides alerts and advice for spotting and dealing with email scams, known as phishing, and more targeted campaigns known as spear-phishing that focus on personal characteristics, interests or lines of work.

“Employees are privy to important and sensitive information, and as a result, often receive malicious emails that are intended to provide cyber intruders access to this information,” the agency says.

The RCMP said it is aware of this latest malware threat, but is not aware of any reported victims.

“We always urge caution in handling unsolicited email and we suggest recipients avoid opening attachments or clicking links from unknown senders. If you are a victim of cybercrime, report it to your local police and the Canadian Anti-Fraud Centre,” said spokeswoman Catherine Fortin.

U.S. cybersecurity firm Sophos said last week that it had learned of a scam that used fake emails pretending to be safety instructions from the World Health Organization.

“Fortunately, at least for fluent speakers of English, the criminals have made numerous spelling and grammatical mistakes that act as warning signs that this is not what it seems,” Sophos said in a blog post dated Feb. 5.

Proofpoint said in its posting that the narrowly focused campaign it detected seems to originate from Russia and Eastern Europe but there’s no evidence linking the actors to a known criminal group.

However, it says the attackers seem to be sophisticated and have targeted industries that are susceptible to shipping disruptions including manufacturing, industrial, finance, transportation, pharmaceutical and cosmetic companies.

“A coronavirus-related shipping supply disruption would negatively impact each of the company types listed above and it’s clear these attackers are aware that a major event like coronavirus can have secondary impacts on industries.

“This awareness demonstrates not just technical sophistication, but economic sophistication as well,” Proofpoint said in its article.

Proofpoint advised workers to exercise caution when presented with coronavirus-themed email messages and attachments, as well as links and websites that could be used by criminals as lures.

Meanwhile, health officials in Canada have repeatedly stressed that the coronavirus currently poses a low risk to the public in this country. Seven cases have been identified in Canada, while worldwide, the illness known as 2019-nCoV has sickened more than 37,000 people and killed more than 800, nearly all in China.

Nevertheless, Canadians are being urged to remain vigilant against infection, with medical experts advising good hygiene practices such as washing hands frequently and coughing or sneezing into tissue.

— with a file from Cassandra Szklarski in Toronto

This report by The Canadian Press was first published Feb. 10, 2020.

Report Error Submit a Tip

More Stories

Hydro reports $446-M loss in 2025-26, points to fourth drought year in past five

Scott Billeck 3 minute read Preview

Hydro reports $446-M loss in 2025-26, points to fourth drought year in past five

Scott Billeck 3 minute read Yesterday at 6:38 PM CDT

Manitoba Hydro posted a $446-million loss in 2025-26, as drought conditions slashed hydroelectric generation, forcing the Crown corporation to buy more power while leaving it with less electricity to sell outside the province.

The loss was $666 million worse than the $220-million profit Hydro had budgeted. The utility posted a $63-million loss the previous year, according to the utility’s annual report released Tuesday.

Hydro said the 2025-26 fiscal year, which ended on March 31, marked its fourth low-water year in the past five years, among the worst stretches of water-flow conditions in its recorded history.

Hydroelectric generation fell 23 per cent to 24 billion kilowatt-hours from 31 billion the previous year, leaving Hydro a net importer of electricity.

Read
Yesterday at 6:38 PM CDT

Cyber campaign exploiting coronavirus fears

David Paddon, The Canadian Press 4 minute read Preview

Cyber campaign exploiting coronavirus fears

David Paddon, The Canadian Press 4 minute read Monday, Feb. 10, 2020

TORONTO - Criminal groups are exploiting fears over the recent novel coronavirus outbreak in an email phishing campaign directed at the global shipping industry, according to a report issued Monday by a California-based cybersecurity firm.

Proofpoint said the new campaign uses emails with bogus Microsoft Word attachments that are designed to install a type of malware known as AZORult.

AZORult has been around since at least 2016 and can be used to install ransomware, which is designed to lock legitimate users out of their computer systems until a ransom is paid.

"In these (coronavirus-related) attacks, we don't see AZORult downloading ransomware currently," Proofpoint said.

Read
Monday, Feb. 10, 2020

Night terrors

AV Kitching 7 minute read Preview

Night terrors

AV Kitching 7 minute read Monday, Oct. 20, 2025

Before we go any further, let me just unequivocally state: Six Pines is not for the weak.

I was so terrified my mind has effectively erased the entire experience.

I shall do my best to give you a comprehensive, cohesive review of the night my friend and I visited, but please forgive the lack of detail.

What you are about to read are snatches of memories, dragged kicking and screaming from the depths of my fear-addled brain, which is, even as I type, trying to block all attempts of retrieval.

Read
Monday, Oct. 20, 2025

No dog? No problem Local program offers offices pup for a day

AV Kitching 4 minute read Preview

No dog? No problem Local program offers offices pup for a day

AV Kitching 4 minute read Saturday, Nov. 1, 2025

Brandt and Paisley are raring to start their new jobs.

They’ve passed their assessment tests, aced their personality evaluations, received all the relevant vaccinations and are getting ready to greet their colleagues at their respective places of employment.

But instead of hellos and handshakes, they’ll most likely be giving their co-workers tail wags and face licks. Not that anyone in the office will mind.

The doggie duo are part of Business Buddies, a new program from the city’s Animal Services Agency which sees canines in the facility spending the afternoon with local businesses.

Read
Saturday, Nov. 1, 2025

‘In Normandy, we remember’

Aaron Epp 4 minute read Preview

‘In Normandy, we remember’

Aaron Epp 4 minute read Saturday, Sep. 26, 2026

Travelling nearly 7,000 km from his home in France to Winnipeg gave Gabriel Zaranski a new perspective on warfare.

“It’s very different to speak about war in school (than) to speak with real people who (have fought) in a war,” he said. “We can feel the emotion when they speak … The testimony has more impact when it’s real soldiers.”

Zaranski is one of 14 Grade 12 students from Bayeux, a town in France’s Normandy region, in Winnipeg this week for a learning tour.

The students, who attend Lycée Arcisse de Caumont high school, met on Saturday with veterans from the Queen’s Own Cameron Highlanders of Canada, a local military regiment, to discuss their studies and the regiment’s role in the Second World War.

Read
Saturday, Sep. 26, 2026

Some of the lives lost in Nova Scotia shootings

The Canadian Press 10 minute read Preview

Some of the lives lost in Nova Scotia shootings

The Canadian Press 10 minute read Tuesday, Apr. 21, 2020

PORTAPIQUE, N.S. - The victims in one of Canada's worst mass killings include an RCMP officer, a teacher, two nurses, neighbours of the shooter and two correctional officers killed in their home.

Here is a look at some of the lives lost:

Lillian Hyslop

Hyslop was killed while out for a morning stroll in Wentworth Valley, N.S. on Sunday morning, says neighbour and fellow walker Heather Matthews.

Read
Tuesday, Apr. 21, 2020