Cybercriminals rapidly adopted coronavirus as a global social-engineering lure, using pandemic-themed emails to drive business email compromise, credential phishing, malware delivery, and large-scale spam across multiple countries and sectors. Proofpoint reported campaigns targeting organizations in Italy, the Czech Republic, the United States, Canada, Australia, and Turkey, as well as industries including healthcare, education, manufacturing, media, advertising, and hospitality. Attackers frequently impersonated trusted public-health institutions such as the WHO, CDC, and national health agencies to make messages appear legitimate and increase click-through rates.
The activity included highly tailored phishing against healthcare firms, fake employee surveys designed to steal OWA credentials, and region-specific lures written in local languages, including Italian. Proofpoint linked portions of the activity to known threat actors including TA505, TA542, and TA564, and observed malware families such as Ostap, The Trick banker, Get2, SDBbot, Ursnif, GuLoader, Agent Tesla, and Remcos. The report found that coronavirus had become a near-universal pretext for cybercrime, enabling both opportunistic and targeted attacks at global scale.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
By March 18, 2020, Proofpoint described coronavirus as a near-universal social-engineering lure across global cybercrime campaigns. The company reported abuse of trusted brands such as the WHO and CDC and documented targeting across multiple countries, languages, and industries.
On March 16, 2020, Proofpoint observed an email campaign impersonating the Philippines customs agency. The campaign delivered Remcos RAT to various international companies.
Also on March 10, 2020, Proofpoint observed a campaign spoofing the Public Health Agency of Canada and targeting Canadian users described as parents and guardians. A macro-enabled Word document installed the Ursnif banker, and Proofpoint attributed the activity to TA564.
On March 10, 2020, Proofpoint observed thousands of coronavirus-themed emails primarily targeting pharmaceutical and manufacturing companies in the United States. The malicious Excel attachment executed the Get2 loader, and Proofpoint attributed the campaign to TA505.
A campaign observed on March 5, 2020 used an attachment named COVID 19_List_cities_names.xlam and attempted to exploit Equation Editor vulnerabilities. The exploit chain downloaded GuLoader, which then delivered Agent Tesla.
In March 2020, attackers targeted users in Italy and the Czech Republic with malicious Word macro documents posing as updates from local medical professionals and the WHO. The documents dropped the Ostap JavaScript downloader, which then downloaded the red5 variant of The Trick banker.
In early March 2020, Proofpoint observed a small spam campaign targeting U.S. media and advertising companies to promote coronavirusmedicalkit[.]com. The site advertised free COVID-19 testing kits but added a $10 fee at the end of the ordering process.
On February 26, 2020, Proofpoint observed an Italian-language credential phishing campaign targeting users in Italy. The landing page used coronavirus-themed graphics to lure victims.
Proofpoint researchers tracked attackers leveraging coronavirus themes across cybercrime activity starting on January 29, 2020. The activity included business email compromise, credential phishing, malware delivery, and spam campaigns.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.