CoronaVirus
- First seen
- 2020-03-01 00:00:00
- Malware type
- ransomware, trojan, wiper
- Last IoC activity
- 2026-07-22 04:24:51
- Profile updated
- 2026-07-07 13:46:27
Targeted industries: healthcare-and-pharmaceutical technology-and-telecommunications
Context
A new ransomware called CoronaVirus has been distributed through a fake web site pretending to promote the system optimization software and utilities from WiseCleaner. With the increasing fears and anxiety of the Coronavirus (COVID-19) outbreak, an attacker has started to build a campaign to distribute a malware cocktail consisting of the CoronaVirus Ransomware and the Kpot information-stealing Trojan. This new ransomware was discovered by MalwareHunterTeam and after further digging into the source of the file, we have been able to determine how the threat actor plans on distributing the ransomware and possible clues suggesting that it may actually be a wiper.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Coronavirus_Ransomware_Auto (yara-rule)
Reports & references
- bleepingcomputer.com — New Coronavirus Ransomware Acts As Cover For Kpot Infostealer (report)