Researchers analyzed multiple COVID-themed Windows malware samples, including CoViper and Covid22, that use pandemic-related lures before deploying destructive components that overwrite the Master Boot Record (MBR) and leave systems unable to boot. In the CoViper case, a PureBasic installer drops several files, creates a hidden %HOMEDRIVE%\COVID-19 folder, establishes persistence, disables Task Manager and some UAC protections, changes the wallpaper and cursor, and repeatedly displays a nuisance GUI. Its end.exe payload reads \\.\PhysicalDrive0, replaces the MBR with attacker code, and shows a taunting message on reboot, with language-specific text for German systems.
Fortinet reported a related sample, Covid22, posing as a fake installer and dropping WipeMBR.exe, which overwrites the first 512 bytes of the MBR without encrypting or stealing files, making the malware destructive but not ransomware. Analysts noted CoViper also backs up the original MBR and contains a hidden recovery shortcut using CTRL+ALT+ESC, suggesting unfinished development or experimentation. Defenders were provided hashes, YARA rules, and recovery guidance, including Windows repair options and the command:
bootrec.exe /fixmbr

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
FortiGuard Labs reported a new Windows malware sample named Covid22 that masquerades as a fake installer, drops several files, and executes WipeMBR.exe to overwrite the first 512 bytes of the Master Boot Record with zeros. The analysis said the malware does not encrypt, steal, or ransom files, and advised using Windows recovery tools such as bootrec.exe /fixmbr to restore affected systems.
A separate technical analysis documented a COVID-19-themed malware sample that extracts components from its resources, creates a hidden %HOMEDRIVE%\COVID-19 folder, disables Task Manager, and uses end.exe to overwrite the MBR with a malicious boot sector and reboot message. The write-up also published hashes and YARA rules for the malware's GUI, runner, and MBR-killing modules.
Avast published an analysis of the CoViper malware family, describing a COVID-19-themed installer that drops multiple components, disables protections, changes system settings, and overwrites the Master Boot Record to make systems unbootable. The report also noted the malware backs up the original MBR and includes a hidden restoration failsafe.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 23 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
fortinet.com
Open sourcetccontre.blogspot.com
Open sourcedecoded.avast.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.