CoronaVirus

First seen
2020-03-01 00:00:00
Malware type
ransomware, trojan, wiper
Last IoC activity
2026-07-22 04:24:51
Profile updated
2026-07-07 13:46:27

Targeted industries: healthcare-and-pharmaceutical technology-and-telecommunications

Context

A new ransomware called CoronaVirus has been distributed through a fake web site pretending to promote the system optimization software and utilities from WiseCleaner. With the increasing fears and anxiety of the Coronavirus (COVID-19) outbreak, an attacker has started to build a campaign to distribute a malware cocktail consisting of the CoronaVirus Ransomware and the Kpot information-stealing Trojan. This new ransomware was discovered by MalwareHunterTeam and after further digging into the source of the file, we have been able to determine how the threat actor plans on distributing the ransomware and possible clues suggesting that it may actually be a wiper.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Coronavirus_Ransomware_Auto (yara-rule)

Reports & references

  • bleepingcomputer.com — New Coronavirus Ransomware Acts As Cover For Kpot Infostealer (report)

External references