Fake coronavirus map infecting computers: Protect yourself now

Coronavirus map by Johns Hopkins University
(Image credit: arcgis.com)

Johns Hopkins University has an extremely useful online map that tracks the spread of the coronavirus that causes COVID-19 in real time. Some crooks are copying the map and using it to spread information-stealing malware.

That's the word from Reason Cybersecurity, a small American-Israeli antivirus maker. Researcher Shai Alfasi detailed in a blog post earlier this week how a downloadable version of the Johns Hopkins map that you can run on your Windows desktop harbors the AZORult Trojan, a piece of malware that has been stealing information since 2016.

We last saw AZORult posing as a ProtonVPN installer file, and its makers even created a perfect copy of the ProtonVPN website to do so. Because Johns Hopkins posted the coronavirus map's source code on GitHub, it may have been inevitable that the AZORult managers cloned the Johns Hopkins map too. 

Alfasi didn't specify how victims might be lured into downloading and installing the poisoned Johns Hopkins map, but it's likely that a link to it is spreading via email and social media. 

If you do install the malevolent map, it will try to "steal browsing history, cookies, ID/passwords, cryptocurrency and more", as Alfasi wrote. 

He added that "there is also a variant of the AZORult that creates a new, hidden administrator account on the infected machine in order to allow Remote Desktop Protocol (RDP) connections", which would let bad guys log into your computer at any time.

Fortunately, it's not hard to avoid infection by this Trojan. First, don't install programs from random links that people send you over social media. Then, make sure to install and run one of the best antivirus programs.

TOPICS
Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.