CoViper
- First seen
- 2020-04-01 00:00:00
- Malware type
- wiper, ransomware
- Profile updated
- 2026-07-07 14:54:54
Context
PCRisk notes that CoViper is yet another Coronavirus/COVID-19-themed malware infection, most likely proliferated as a file related to the pandemic. It operates by rewriting the system Master Boot Record (MBR). It does not delete the original, but rather creates a backup and replaces it with a custom MBR. Typically, malicious software that modifies MBRs do so to prevent the Operating System (OS) from being booted (i.e., started). It also displays a screen-encompassing message, often containing a ransom message - this disables user access to the device.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Coviper (report)
- tccontre.blogspot.com — Covid19 Malware Analysis With Kill Mbr (report)
- decoded.avast.io — Coviper Locking Down Computers During Lockdown (report)