Coronavirus Malware, how to defend yourself from cyber attacks

A new malware attack is targeting home routers by exploiting a **web page related to COVID-19**. Over 1000 users affected in two days, **Coronavirus-themed malware** has quintupled in March: advice on how to defend yourself.

Malware Coronavirus Covid-19
Malware Coronavirus Covid-19
Follow FullPress on Google

Add us to your preferred sources.

Follow this source on Google

Researchers from Bitdefender have recently uncovered a new attack that targets home routers and changes their DNS settings. Hackers target remote management credentials for brute force attacks on Linksys routers to change DNS settings and redirect users to a COVID-19-related webpage that distributes malware (Oski info-stealer). The TinyURL service is used to hide the Bitbucket repository link hosting the malware.

The attack is new, it started on March 18th, and abuses a URL shortening service to mask the payload link as well as Bitbucket (a legitimate code repository) to host the malicious payloads.

“COVID-19 is unfortunately a recurring theme that cybercriminals are exploiting to ensnare victims,” said Liviu Arsene, Senior Cybersecurity Researcher at Bitdefender. “Reports of coronavirus-themed malware have quintupled in March with unscrupulous attackers using phishing scams that leverage misinformation on Coronavirus and fear over medical supply shortages.”

How the Coronavirus Malware Attack Works

It is not uncommon for hackers to use news of strong public interest, such as the ongoing pandemic, to capture users’ attention and send phishing emails with infected attachments; this recent type of attack involving home routers confirms the trend.

Attackers have scanned the internet for vulnerable routers, successfully breaching them – potentially via password brute force attacks – and modifying their IP DNS settings. DNS settings are very important, as they function like a phone book. Every time users type in a website name, DNS services can send them to the corresponding IP address that serves that particular domain name. In short, DNS works more or less like a smartphone’s address book: every time you want to call someone, you just look up their name instead of having to memorize their phone number.

Once hackers change the DNS IP addresses, they can redirect users to webpages controlled directly by them, without anyone noticing.

Below is a list of some of the domains that are being redirected:

  • “aws.amazon.com” 
  • “goo.gl” 
  • “bit.ly” 
  • “washington.edu” 
  • “imageshack.us” 
  • “ufl.edu” 
  • “disney.com” 

When trying to reach one of the above domains, users are effectively redirected to an IP address which displays a message that appears to be from the World Health Organization, asking users to download and install an application that offers instructions and information about COVID-19.

In detail, the malicious payloads are delivered via Bitbucket, the popular web-based hosting service for projects using version control systems. To ensure the victim doesn’t suspect a crime, hackers also abuse TinyURL, the popular URL shortening web service, to hide the link to the Bitbucket payload. The interesting thing is that users believe they have landed on a legitimate webpage, except it is served from a different IP address.

Which Users Are Affected by the Coronavirus Malware

The current number of potential victims in the last two days is estimated at around 1,193, judging by the cumulative number of downloads from Bitbucket repositories found still active.

Bitdefender researchers also discovered that the main affected countries are France, Germany, and the United States, accounting for over 73% of the total. Italy and Spain may be included, as Bitbucket has already blocked two repositories, making it impossible to get a complete picture of the number of victims.

How to Defend Against Coronavirus Malware

In addition to changing the router’s control panel login credentials, users are advised to change their Linksys cloud account credentials, or any remote management account for their routers, to prevent any takeover via attacks using the “brute force” or credential stuffing method.

It is also recommended to ensure the router’s firmware is always updated, as this prevents hackers from exploiting unpatched vulnerabilities to take over the device. Finally, it is important to ensure all devices have a security solution installed that prevents access to phishing or fraudulent websites and the download and installation of malware.

Pubblicato in

Se vuoi rimanere aggiornato su Coronavirus Malware, how to defend yourself from cyber attacks iscriviti alla nostra newsletter settimanale

Be the first to comment

Leave a Reply

Your email address will not be published.


*