Watchout: COVID-19 Malware Can Wipe Your PC
Some malware authors have developed malware that destroys infected systems, either by wiping files or rewriting a computer’s master boot record (MBR). With help from the infosec community, ZDNet has identified at least five malware strains, some distributed in the wild, while others appear to have been created only as tests or jokes.
Rather than using the coronavirus as a means for more power (politicians) or financial gain, this malware appears to be simply destructive.
Of the four malware samples found by security researchers this past month, the most advanced were the two samples that rewrote MBR sectors.
Some advanced technical knowledge was needed to create these strains as tinkering with a master boot record is no easy feat and could easily result in systems that didn’t boot at all.
The first of the MBR-rewriters was discovered by a security researcher that goes by the name of MalwareHunterTeam, and detailed in a report from SonicWall this week. Using the name of COVID-19.exe, this malware infects a computer and has two infection stages. –ZDNet
f632b6e822d69fb54b41f83a357ff65d8bfc67bc3e304e88bf4d9f0c4aedc224
“coronavirus successfully installed”
AnyRun (thanks to @JayTHL): https://t.co/vcEO1MvFfj@demonslay335 pic.twitter.com/6w4ZSnyADy— MalwareHunterTeam (@malwrhunterteam) March 23, 2020
Here’s what you will want to watch for:
In the first phase, it just shows an annoying window that users can’t close because the malware has also disabled the Windows Task Manager.
While users attempt to deal with this window, the malware is silently rewriting the computer’s master boot record behind their back. It then restarts the PC, and the new MBR kicks in, blocking users into a pre-boot screen.
Users can eventually regain access to their computers, but they’ll need special apps that can be used to recover and rebuild the MBR to a working state.
There is another coronavirus-themed malware strain that re-wrote the MBR and it is a far more convoluted malware operation.
The malware’s primary function was to steal passwords from an infected host and then mimic ransomware to trick the user and mask its real purpose.
However, it wasn’t ransomware either. It only posed as one. Once the data-stealing operations ended, the malware entered into a phase where it rewrote the MBR, and blocked users into a pre-boot message, preventing access to their PCs. With users seeing ransom notes and then not being able to access their PCs, the last thing users would thing to do is to check if someone exfiltrated passwords from their apps.
According to analysis from SentinelOne security researcher Vitali Kremez and Bleeping Computer, the malware also contained code to wipe files on the user’s systems, but this didn’t appear to be active in the version they analyzed.
At first this seems like a simple screenlocker, but it infects the MBR as well.
Same MBR as the Coronavirus ransomware found by @malwrhunterteamThe MBR is from a builder by someone called #WobbyChip. https://t.co/DRcNsOq8bu pic.twitter.com/MAAItcaGgI
— Karsten Hahn (@struppigel) March 26, 2020
Norton anti-virus has offered tops to help keep your PC safe from these and other destructive problems. If you can, do a scan of your computer to make sure your anti-virus software is catching all the problems.
Please read the entire article by ZDNet by clicking here.
This article has been contributed by SHTF Plan. Visit www.SHTFplan.com for alternative news, commentary and preparedness info.
Source: https://www.shtfplan.com/headline-news/watchout-covid-19-malware-can-wipe-your-pc_04022020
Anyone can join.
Anyone can contribute.
Anyone can become informed about their world.
"United We Stand" Click Here To Create Your Personal Citizen Journalist Account Today, Be Sure To Invite Your Friends.
Please Help Support BeforeitsNews by trying our Natural Health Products below!
Order by Phone at 888-809-8385 or online at https://mitocopper.com M - F 9am to 5pm EST
Order by Phone at 866-388-7003 or online at https://www.herbanomic.com M - F 9am to 5pm EST
Order by Phone at 866-388-7003 or online at https://www.herbanomics.com M - F 9am to 5pm EST
Humic & Fulvic Trace Minerals Complex - Nature's most important supplement! Vivid Dreams again!
HNEX HydroNano EXtracellular Water - Improve immune system health and reduce inflammation.
Ultimate Clinical Potency Curcumin - Natural pain relief, reduce inflammation and so much more.
MitoCopper - Bioavailable Copper destroys pathogens and gives you more energy. (See Blood Video)
Oxy Powder - Natural Colon Cleanser! Cleans out toxic buildup with oxygen!
Nascent Iodine - Promotes detoxification, mental focus and thyroid health.
Smart Meter Cover - Reduces Smart Meter radiation by 96%! (See Video).