EVA-Technologies URGENT BULLETIN

MARCH 16th 2020

Cyber Threat: COVID-19 Threat Intelligence Landscape (CCTX - CANADA)


Executive summary:
Internal security bulletin from the Canadian Cyber Threat Exchange

This bulletin illustrates ongoing attacks on Canadian companies which are leveraging the Coronavirus crisis.
 
These bulletins should be reviewed with your IT team, and everyone should be made aware of these phishing campaigns which can target all staff.
 
 
Opportunistic Cyber Threat Actors Leverage Coronavirus Themes:
 

  • Following public reporting about the increasing numbers of Coronavirus (COVID-19) cases, multiple threat actor campaigns were observed leveraging the virus and related themes as a lure in phishing and malware activity
  • The increasing use of remote-work and teleconferencing services increases potential cyber risks for enterprises as opportunistic actors tailor phishing and business email compromise activities.   
  • Geopolitical Instability May Impact Longer Term Cyber Threat Activity
 
  • COVID-19 is impacting nation-states with advanced cyber capabilities, potentially prompting some longer-term shifts in cyber activity.
    • Actors with advanced espionage capabilities, such as China, may leverage intellectual property theft and corporate espionage as a means to support economic stability in the long-term.
    • COVID-19 disruption to regimes with advanced cyber capabilities, such as Iran, may prompt political shifts that influence the willingness of those nations to pursue cyber operations impacting the financial sector.
    • A sustained global or localized economic downturn related to COVID-19 may prompt some state-linked actors, such as North Korea, to further leverage cyber crime as a means of revenue generation.

It is assessed that state-sponsored actors from multiple nations are likely to leverage cyber activity as part of a strategy to restore economic stability following an outbreak.
 
 

OBSERVED ATTACK ON CANADIAN COMPANIES #1

 
A member organization detected a large number of inbound emails (approx. 370) from two domains related to the Coronavirus. All emails were dropped at perimeter and determined to be spam. None was determined as malicious.
 
Details:
 
Sender Addresses:
 
  • CoronaVirus[@]pandemicsurvivals.bid
  • Pandemicsurvival[@]surveuvcoronavirus.us

Email Subjects:

 
  • Corona Virus is spreading - Learn how to survive
  • Corona Virus - Do this before it's too late...
  • Corona worse than Ebola?
  • EMERGENCY EMAIL
  • Feeling Helpless Against Corona?


OBSERVED ATTACK ON CANADIAN COMPANIES #2
 
Summary 
CCTX SOC received a submission from a member organization sharing threat indicators observed from Coronavirus themed malicious spam campaigns.
 
Description 
Below are IOCs from recent COVID-19 spam campaigns
 
browserinstallup[.]com/1[.]7z 
browserinstallup[.]com/1[.]exe 
corona-map-data[.]com 
F195F28AD0823FD6430B8999FB112BBECBA81538B7EB28B88D0925EA4E8E5C95 
63FCF6B19AC3A6A232075F65B4B58D69CFD4E7F396F573D4DA46AAF210F82564 
hxxps[:]//corona-virus-map[.]net/data 
corona-virus-map[.]net/data/ 
corona-virus-map[.]net/
 
corona-virus-map[.]net 
74aeb7771eb0762c39cceb8c68f5fd58c9ce7119971022b0131251df64ffde56
 
668f8867d1179cbbac2f0c052a1fbb5a 
fcecd62c1bd7c4f3806213dc126f6fa1e6e15215acd01817693dadc39fc84cad