A COVID-19-themed malware campaign used a fake WiseCleaner download site at wisecleaner[.]best to deliver a loader named WSHSetup.exe, which fetched both CoronaVirus ransomware and the Kpot information stealer from trynda[.]xyz and related domains. Researchers reported that Kpot executed first, harvesting credentials and other sensitive data from browsers, VPN, RDP, email, chat, FTP, and cryptocurrency wallets before contacting attacker-controlled infrastructure and deleting itself, indicating that data theft was a primary objective of the intrusion.
CoronaVirus ransomware then encrypted files with AES, appended the prefix coronavi2022@protonmail.ch___ to filenames, dropped a ransom note named CoronaVirus.txt, and demanded a relatively small Bitcoin payment via contact address coronaVi2022@protonmail.ch. The malware also modified the MBR, registered pre-boot execution through the BootExecute registry value, displayed lock-screen ransom messages before Windows loaded, and attempted to hinder recovery by deleting shadow copies and backups, leading analysts to assess that the ransomware likely served in part as cover for the broader Kpot credential-theft operation.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
MBSD published an analysis detailing how WSHSetup.exe delivered Kpot as file1.exe and CoronaVirus ransomware as file2.exe, along with the malware's credential theft and MBR/BootExecute behavior. The report also assessed that the ransomware may have helped conceal the information-stealing activity.
The fake WiseCleaner site used in the campaign became inaccessible after late March. This marked the apparent end of availability for that observed distribution point.
Researchers reported that the fake WiseCleaner download site at wisecleaner[.]best existed by at least late February and was used to distribute the fake installer WSHSetup.exe. That installer downloaded Kpot stealer and CoronaVirus ransomware from trynda[.]xyz.
The CoronaVirus ransomware campaign was active around the beginning of March 2020. Analysis indicated the operation paired a COVID-19-themed ransomware payload with the Kpot information stealer, suggesting credential theft was a primary objective.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.