Coronavirus 'cure' emails are spreading malware, stealing passwords

Female doctor writing on a clipboard.
(Image credit: ReaLiia/Shutterstock)

Hey, there's a secret cure for the Wuhan coronavirus, but the government won't let you use it! Click here for more!

If you fell for that, then you might fall for similar phishing emails that promise details of this supposed plot against humanity and/or offer to provide tips on how to prevent becoming infected by the disease. 

The catch is that in order to read any of that crucial information, you'll have to provide credentials to your personal or workplace email accounts, or open a document that will infect your PC with some particularly nasty malware that can steal your passwords or fully take over your computer.

So say the researchers at Proofpoint, who posted examples of these criminal scams in a blog post yesterday (Feb. 13). 

"These latest examples serve as a reminder that users should be watchful and exercise caution where Coronavirus-themed emails and websites are concerned," wrote Proofpoint's Sherrod DeGrippo.

The best antivirus software should stop the malware, but it won't always stop the phishing attacks, which rely on human, not digital, weakness. To stop those, ask yourself why a random site wants account credentials, and check the URL of each page to make sure you're actually where you should be.

What's in the coronavirus scam email

"The world has been struggling to contain this deadly virus developed and sprayed by wicked scientists to reduce the population of the world so the government will have control over you," reads one email that Proofpoint cited. "Our secret medical scientist team has developed the cure ... For those interested to secure their lives kindly reply and get more information about shipping and delivery to you."

The email presents a link to a "free health guideline" that leads to a website asking for the victim's DocuSign username and password. DocuSign is used by corporations, PayPal and the U.S. Internal Revenue Service to authenticate documents, so those credentials would be immensely valuable to thieves.

A few other emails dial down the conspiracy theories, but nonetheless pretend to come from some authority — the World Health Organization (WHO), a (fake) Australian government agency, a company president — and offer to give you safety tips in an attached documents or included web link. 

Phishing, keylogging and total control of your PC

The company president's email contains a Microsoft Word file that links to a phishing site asking for your corporate network credentials. The WHO email has a "CoronaVirus Safety" attachment that is actually a keylogger, capturing everything you type and sending it to the attacker. The Australian email takes you to another phishing site that asks for your Adobe Creative Cloud account credentials.

Proofpoint's last example is worst of all. It also pretends to come from corporate leadership and offer coronavirus safety tips, but it doesn't just try to steal your account credentials. Instead, an attached file opens up to install the NanoCore RAT, a remote-access Trojan that gives a far-off attacker total control over your PC.

TOPICS
Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Latest in Malware & Adware
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Malware
Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs
An FBI agent typing on a computer
FBI issues warning to millions of Americans to avoid these websites that can steal your passwords and banking info
A hacker typing quickly on a keyboard
New MassJacker malware is hijacking digital wallets to steal large sums from users
A person trying to set up a new Wi-Fi router
Thousands of TP-Link routers have been infected by a botnet to spread malware
A smartphone screen displaying the Android name and logo next to a sign reading 'MALWARE'.
Fake Google Play Store pages are spreading Trojan malware that can steal your financial data
Latest in News
Apple Watch Series 10
Future Apple Watch models could get a surprising new feature — what we know
iPhone 16 Pro vs iPhone 16 Pro Max in hand showing displays
Forget iPhone 17 — iPhone 18 could get this huge upgrade
The new Husqvarna iQ series robot lawn mower.
Husqvarna’s new robot mowers offer GPS for less
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
NYTimes Connections
NYT Connections today hints and answers — Sunday, March 23 (#651)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #385 (Sunday, March 23 2025)