Threat actors widely exploited COVID-19 news, relief programs, testing, and vaccine demand to increase the effectiveness of phishing and malware campaigns, while mostly reusing established malware and infrastructure. Microsoft reported an eleven-fold jump in COVID-19-themed attacks after the disease was formally named, but said these campaigns remained a small share of overall activity and largely repurposed existing tradecraft. Palo Alto Networks tracked 69,950 pandemic-related phishing URLs from early 2020 through early 2021, including a 530% rise in vaccine-themed phishing and a 189% increase in pharmacy- and hospital-related lures, with many pages harvesting Microsoft 365, Outlook, and webmail credentials or personal and financial data from newly created and compromised sites.
The same social-engineering theme was used to deliver a broad mix of malware across desktop and mobile platforms. Researchers linked COVID-19 spam and fake sites to loaders and commodity malware including GuLoader, Parallax RAT, Remcos, Agent Tesla, NanoCore, NetWire, AzorUlt, FormBook, TrickBot, and MetaMorfo, often relying on malicious attachments, macro-enabled Office files, or exploits such as CVE-2017-11882; Microsoft and others warned users not to enable macros in untrusted documents. More disruptive campaigns included Netwalker ransomware delivered through a CORONAVIRUS_COVID-19.vbs attachment, Android fraud via the Ginp trojan’s fake “Coronavirus Finder,” an Android SLocker variant that locked devices with COVID-19-themed ransom messages, and later low-volume phishing that used WHO-themed documents to install Nerbian RAT with anti-analysis and persistence features.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
28 events from the most recent confirmed update back to the earliest known activity.
Proofpoint published analysis of Nerbian RAT, describing its anti-analysis checks, encrypted configuration, SSL-based C2 communications, and likely capabilities including keylogging and screen capture. The company said the campaign disproportionately impacted entities in Italy, Spain, and the United Kingdom.
Proofpoint observed a low-volume phishing campaign beginning on April 26, 2022 that used COVID-19 and WHO-themed lures to distribute a newly identified Go-based malware family it named Nerbian RAT. The infection chain relied on macro-enabled Word documents, a PowerShell downloader, and a Golang dropper that installed the RAT and created scheduled-task persistence.
Palo Alto Networks Unit 42 analyzed phishing activity from January 2020 through February 2021 and identified 69,950 phishing URLs linked to COVID-related topics, including 33,447 directly tied to COVID-19 itself. The report highlighted fake vaccine-registration pages impersonating Pfizer and BioNTech and credential theft targeting Microsoft and Office 365 accounts.
Unit 42 found that attackers shifted from PPE and relief-program lures to vaccine registration themes from late fall 2020 onward. It reported a 530% increase in vaccine-related phishing and a 189% increase in phishing related to or targeting pharmacies and hospitals from December 2020 to February 2021.
G Data reported that cybercriminals widely used pandemic-themed spam emails, phishing links, and fake websites to deliver established malware families including GuLoader, Parallax RAT, Remcos, NanoCore, NetWire, and Agent Tesla. It also described destructive and nuisance payloads such as an MBR-overwriting "Coronavirus.exe" sample and COVID-themed jokeware.
CISA issued an Activity Alert stating that attackers continued to access U.S. government and commercial networks after Pulse Secure VPN appliances were patched for CVE-2019-11510, because credentials stolen before patching were still valid. The alert documented incident response cases involving lateral movement, persistence, exfiltration, and ransomware, and provided detection guidance, IOCs, and mitigation recommendations including password resets.
On August 27, 2020, the Health Sector Cybersecurity Coordination Center released report 202008271653 describing a COVID-19 PPE-themed phishing campaign that delivered Agent Tesla RAT. The emails used RAR or Gzip attachments that installed the malware when executed.
Microsoft published telemetry findings concluding that COVID-19-themed attacks accounted for less than two percent of monthly attacks and did not significantly change overall malware detection volumes. It emphasized that attackers mainly repurposed known malware and phishing infrastructure while changing social-engineering themes.
Microsoft warned of an ongoing large-scale phishing campaign using Johns Hopkins-themed coronavirus emails and malicious Excel attachments to install the legitimate NetSupport Manager tool as a RAT. The campaign used hundreds of obfuscated Excel files that downloaded the same payload, which was saved as dwm.exe and could enable further compromise, credential theft, and lateral movement.
Bitdefender described an Android SLocker variant distributed as a sideloaded app named "Koronavirus haqida" that locked victims' screens and demanded payment through Paynet. The sample persisted across reboot but did not encrypt user data.
IBM X-Force IRIS reported suspicious cyber activity beginning on March 30, 2020 that targeted a German multinational corporation involved in government PPE procurement and its third-party supply chain partners. The researchers tied the activity to infrastructure at 178.159.36.183 and found more than 280 URLs, many containing Base64-encoded email addresses of executives in operations, finance, procurement, and partner organizations across multiple sectors.
Cisco analyzed a COVID-19-themed malspam campaign targeting primarily Brazilian citizens that delivered the MetaMorfo banking trojan through malicious attachments, redirect domains, and a ZIP archive. One observed lure referenced a WhatsApp conversation history file dated 03/25/2020.
Cisco said enterprise customers made 562,144 queries to 8,080 COVID-19-related domains on February 19, rising to 11,287,190 queries to 47,059 such domains by March 19. It reported that 4% of the March 19 domains were blocked as malicious.
Proofpoint reported multiple coronavirus-themed email campaigns, including a TA505 downloader campaign targeting U.S. healthcare, manufacturing, and pharmaceutical organizations and a TA564 campaign spoofing the Public Health Agency of Canada to deliver the Ursnif banking trojan to Canadian users. The report highlighted COVID-19 lures being used across phishing, malware delivery, BEC, and fake landing-page activity.
Microsoft said that by the end of March 2020, every country in the world had experienced at least one COVID-19-themed cyberattack. The company also noted that defenders began increasing phishing awareness and training starting in April.
K7 Labs reported that GuLoader samples contacting Google Drive rose from about 2,100 in February to about 3,300 by the end of March, with OneDrive-linked samples also increasing. The campaign used COVID-19-themed spam documents, macros, and CVE-2017-11882 to deliver GuLoader and downstream malware such as FormBook.
BleepingComputer reported a coronavirus-themed phishing campaign distributing Netwalker ransomware through a malicious VBS attachment named "CORONAVIRUS_COVID-19.vbs." The script dropped and launched an embedded executable that encrypted files and left ransom notes.
Microsoft reported that COVID-19-themed attacks peaked globally in the first two weeks of March 2020 before settling into a higher baseline. The company said these campaigns largely reused existing malware, infrastructure, and tradecraft rather than introducing novel threats.
Kaspersky reported a Ginp Android banking trojan campaign that displayed a fake "Coronavirus Finder" page and tricked victims into entering payment card data. The activity was observed mainly in Spain and used a newer Ginp variant tagged "flash-2."
Cisco Talos reported multiple malware campaigns using coronavirus-themed lures, primarily malspam, to distribute malware including Emotet and NanoCore RAT, and published indicators for related samples. Talos also identified coronavirus-themed Parallax RAT and a destructive wiper sample in malware repositories, while noting some similarly named files were only jokes or unwanted applications.
Microsoft said cybercriminals began actively deploying opportunistic COVID-19-themed campaigns after the WHO named the disease COVID-19 on February 11, and observed an eleven-fold increase in the following week. Unit 42 also observed a 313% increase in phishing attacks directly related to COVID-19 between January and February 2020.
IBM X-Force reported a malspam campaign using fear of the coronavirus outbreak to deliver Emotet via malicious Word attachments. The Japanese-language emails impersonated disability welfare service providers and used localized infection notices for prefectures including Gifu, Osaka, and Tottori to lure recipients into enabling macros.
Parallax RAT first appeared in December 2019 and was later delivered through COVID-19-themed GuLoader campaigns.
MetaMorfo was first seen in April 2018 targeting Brazil before later being used in a COVID-19-themed malspam campaign.
Remcos was first seen in the wild in the second half of 2016 and was initially used in spear-phishing campaigns targeting Turkish organizations.
Agent Tesla was first seen in 2014 and later remained active as a commodity RAT and information stealer used in pandemic-era attacks.
NanoCore was first seen in the wild in 2013, before later being reused in COVID-19-themed malware delivery activity.
NetWire was described as emerging in the wild during the first half of 2012 and later became one of the established RAT families reused in pandemic-themed campaigns.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 367 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
17 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourceproofpoint.com
Open sourceunit42.paloaltonetworks.com
Open sourcegdatasoftware.com
Open sourceproofpoint.com
Open sourceblog.talosintelligence.com
Open sourceexchange.xforce.ibmcloud.com
Open sourcesupport.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.