COVID-19 Exploited by Malicious Cyber Actors

April 10th, 2020

Read The Full Alert Below In PDF form

Alert 4.10.2020(new)

 

This is a joint alert from the United States Department of Homeland Security (DHS) Cybersecurity and
Infrastructure Security Agency (CISA) and the United Kingdom’s National Cyber Security Centre (NCSC).
This alert provides information on exploitation by cybercriminal and advanced persistent threat (APT) groups of the current
coronavirus disease 2019 (COVID-19) global pandemic. It includes a non-exhaustive list of indicators of compromise
(IOCs) for detection as well as mitigation advice.
Both CISA and NCSC are seeing a growing use of COVID-19-related themes by malicious cyber actors. At the same time,
the surge in teleworking has increased the use of potentially vulnerable services, such as virtual private networks (VPNs),
amplifying the threat to individuals and organizations.
APT groups and cybercriminals are targeting individuals, small and medium enterprises, and large organizations with
COVID-19-related scams and phishing emails. This alert provides an overview of COVID-19-related malicious cyber
4/10/2020
2/7
activity and offers practical advice that individuals and organizations can follow to reduce the risk of being impacted. The
IOCs provided within the accompanying .csv and .stix files of this alert are based on analysis from CISA, NCSC, and
industry.
Note: this is a fast-moving situation and this alert does not seek to catalogue all COVID-19-related malicious cyber
activity. Individuals and organizations should remain alert to increased activity relating to COVID-19 and take proactive
steps to protect themselves.

GO TO ALL ALERTS

Members