In another COVID-19 scam, the email security firm Inky has found emails that are impersonating President Trump and Vice President Mike Pence. The emails state that they are the latest “Coronavirus Guidelines for America” and prompts the recipient to click a link that takes the user to a webpage that impersonates the White House and contains a link to “download and read the full document.” The downloaded file contains a malicious Word document that then prompts the user to “Enable Editing” and “Enable Content” to view it. Once those are enabled, malicious macros will launch and install malware onto the recipient’s computer. Even though the site pushing the malware has been taken down, it is unclear as to how many people have received the link or what malware strain was being used.
Written by: Nataliia Zdrok, Threat Intelligence Analyst at Binary Defense Russia’s invasion of Ukraine increased