Monday, November 25, 2024
HomeCyber AttackFake COVID-19 Test Results Drop King Engine Ransomware

Fake COVID-19 Test Results Drop King Engine Ransomware

Published on

According to Cofense Intelligence researchers, a new version of Hentai OniChan Ransomware dubbed “King Engine” is being delivered during a Coronavirus-themed phishing campaign.

The new variant called King Engine exfiltrates data and demands a huge amount as ransom, which is significantly on top of previously analysed versions of Hentai OniChan campaigns.

In previous campaigns, cybercriminals used the Berserker variant of this ransomware, which used similar phishing emails to focus on the financial and energy sectors and did not exfiltrate data. 

- Advertisement - SIEM as a Service

However, this is a tough campaign that uses the COVID-19 scare to compromise the victim’s device.

The spike in coronavirus cases during October has led to more testing and makes this sort of phishing campaign even more threatening. 

This campaign uses common tactics, techniques, and procedures (TTPs) to reach end-users and deliver Hentai OniChan Ransomware that belongs to the Quimera Ransomware family. 

During this scam, attackers are sending emails that contain the recipient’s Coronavirus test result in an attachment, which is simply a lure to convince the victim to open the attachment.

Phishing Email Delivering Hentai OniChan Ransomware

As shown in the image above, the e-mail provides a password for opening the document and mentions the name of a nurse who can answer their questions. However, it is a trick to form an e-mail that appears legitimate.

Hentai OniChan Ransomware 

Cofense Intelligence researchers stated that Hentai OniChan Ransomware was discovered in September and is found in an environment protected by Symantec, Proofpoint, Cisco IronPort, Microsoft ATP, and TrendMicro.

The downloadable PDF or HTML attachment contains components to drop and run the ransomware executable encrypting victims and holding them hostage, promising to supply decryption upon receipt of the ransom payment.

Once the target’s files are encrypted, the ransom note is provided to the victim affected which contains the way to pay the ransom, price to be paid 50 BTC (£524,725 – €584,299- $676,000), Bitcoin address, timeline, and contact email address.

Conclusion

As the COVID-19 pandemic is considered the most crucial global health calamity of the century, it is no surprise that malware authors are exploiting the pandemic. An outsized number of individuals have taken a test and awaiting results.

So if you are on the web, you are susceptible to such attacks. Ensure you don’t fall to these scare tactics and don’t download or open files from anonymous users.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Also Read

Infamous Maze Ransomware Operators Shuts Down Operations

Vermont Hospitals Now Latest Victim of Ransomware Attacks

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Threat Actors Exploit Google Docs And Weebly Services For Malware Attacks

Phishing attackers used Google Docs to deliver malicious links, bypassing security measures and redirecting...

Python NodeStealer: Targeting Facebook Business Accounts to Harvest Login Credentials

The Python-based NodeStealer, a sophisticated info-stealer, has evolved to target new information and employ...

XSS Vulnerability in Bing.com Let Attackers Send Crafted Malicious Requests

A significant XSS vulnerability was recently uncovered in Microsoft’s Bing.com, potentially allowing attackers to...

Meta Removed 2 Million Account Linked to Malicious Activities

 Meta has announced the removal of over 2 million accounts connected to malicious activities,...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Threat Actors Exploit Google Docs And Weebly Services For Malware Attacks

Phishing attackers used Google Docs to deliver malicious links, bypassing security measures and redirecting...

Python NodeStealer: Targeting Facebook Business Accounts to Harvest Login Credentials

The Python-based NodeStealer, a sophisticated info-stealer, has evolved to target new information and employ...

Nearest Neighbor Attacks: Russian APT Hack The Target By Exploiting Nearby Wi-Fi Networks

Recent research has revealed that a Russian advanced persistent threat (APT) group, tracked as...