CoViper

First seen
2020-04-01 00:00:00
Malware type
wiper, ransomware
Profile updated
2026-07-07 14:54:54

Context

PCRisk notes that CoViper is yet another Coronavirus/COVID-19-themed malware infection, most likely proliferated as a file related to the pandemic. It operates by rewriting the system Master Boot Record (MBR). It does not delete the original, but rather creates a backup and replaces it with a custom MBR. Typically, malicious software that modifies MBRs do so to prevent the Operating System (OS) from being booted (i.e., started). It also displays a screen-encompassing message, often containing a ransom message - this disables user access to the device.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Coviper (report)
  • tccontre.blogspot.com — Covid19 Malware Analysis With Kill Mbr (report)
  • decoded.avast.io — Coviper Locking Down Computers During Lockdown (report)

External references