CoronaVirus ransomware is a Windows ransomware family that emerged in early 2020 and used COVID-19-themed branding to capitalize on pandemic-related attention. It has been observed in campaigns where a fake software installer acted as a loader for both the ransomware and the Kpot infostealer, indicating a dual-purpose intrusion in which credential and data theft preceded file encryption. Analysts have assessed that, in at least some operations, the ransomware component likely served partly as cover for the theft activity rather than as the sole monetization mechanism.
On execution, CoronaVirus copies itself to a temporary location, seeks administrative privileges, and establishes persistence. It encrypts selected user files, drops ransom notes, and configures the system to present ransom messaging at multiple stages of boot and logon. A notable feature is direct modification of the master boot record, including replacement of boot code so a ransom message is displayed before Windows fully loads. It also registers a native application for pre-boot execution through BootExecute, creating an additional lock-screen style ransom display. Some observed behavior indicates the malware may fail to restore the original boot record reliably, potentially leaving systems unbootable.
The ransomware also impedes recovery by deleting volume shadow copies and Windows backup data. Additional observed behavior includes changing the system drive label and repeatedly prompting for elevation until administrative access is granted. In associated campaigns, the preceding Kpot payload stole credentials and other sensitive information from browsers, mail clients, chat applications, VPN and remote access tools, FTP software, gaming platforms, and cryptocurrency-related stores before removing itself.
CoronaVirus has been linked to fake utility download sites and malicious installers used as downloaders. It targets Windows systems and combines ransomware, boot-level disruption, persistence, privilege escalation, and defense-evasion behavior with broader post-compromise activity associated with companion infostealer deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
New ransomware family distributed from fake WiseCleaner sites, paired with Kpot Infostealer and displaying a customized ransom message at boot.
Fake-installer-delivered ransomware that is downloaded as file2.exe after execution of a bogus WiseCleaner installer. It attempts UAC elevation, modifies the MBR/boot process to display ransom notes, creates a native application via BootExecute to show a pre-Windows ransom message, encrypts files, drops ransom-note text files, and deletes shadow copies and Windows backups. The article notes it may also serve to conceal prior credential theft by Kpot.
Named ransomware mentioned only as another Coronavirus-themed threat example.
Ransomware/MBR-locking malware active in early March 2020 that encrypts files with AES, appends a prefix to encrypted filenames, drops the ransom note CoronaVirus.txt, modifies BootExecute for pre-boot execution, overwrites the MBR, adds itself to Windows startup, and is described as a cover-ransomware used primarily to facilitate Kpot infostealer infection rather than maximize ransom revenue.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.