Nasty Trickbot malware exploits people’s Coronavirus fears

(Image credit: Shutterstock)

Malicious hackers are using people’s fear of the Coronavirus to spread malware, known as Trickbot, by emailing an official-looking message that claims to contain a document listing some helpful precautions. Instead, it contains an infected Word document.

The email has been sent to Italian email addresses. Italy has been one of the most affected countries by Coronavirus, and the spam emails are preying on its residents’ understandable concern about the disease.

The emails contain the subject line “coronavirus: informazioni importanti su precauzioni” and claim to be sent by “Dr. Penelope Marchetti”. 

It then goes on to warn, in Italian, that “due to the fact that cases of coronavirus infection are documented in your area, the World Health Organization has prepared a document that includes all necessary precautions against coronavirus infection. We strongly recommend that you read the document attached to this message!”.

Malware-infested document 

If recipients open the Word document, the document tries to run a macro, which is a programmable series of inputs in a program. Usually, macros can be used to make shortcuts for more complex commands in certain programs, but attackers can use macros to run malicious programs and code.

According to security firm Sophos, which detected the threat, when the Word document is opened, a VBA macro file (vbaProject.bin), and several Word-related XML files are placed on the victim’s hard drive, and these connect to a PHP script on a remote server, which passes information about the PC, and downloads a malicious virus onto it.

This is the screen that appears when victims open the email attachment

This is the screen that appears when victims open the email attachment (Image credit: Sophos)

If a user has macros disabled in Microsoft Word, then a message is displayed asking the victim to enable editing and enable content because “this document was created in an earlier version of Microsoft Office Word.” If the victim follows these steps, it allows the malicious code to be run.

As Sophos points out, this malware has been doing the rounds before, but used spam emails that tried to trick people into opening the document, as it had information about credit cards or loans.

Unfortunately, the malicious users have realized that preying on people’s Coronavirus fears is a more effective way to trick people into opening the document.

Even though the emails are targeting Italians, it’s likely people in other countries could be targeted as Coronovirus spreads.

Stay safe

To make sure you don’t fall victim to this scam, or a similar one, there are certain precautions you should take.

First of all, never open an unsolicited email from someone you don’t recognise, and especially do not open any attachments to those emails.

If you are concerned about Coronavirus, visit official websites of organisations such as The World Health Organization. Official government correspondence will never be via unsolicited emails, and they will never ask you to open an attachment (especially a Word document) for important information.

TOPICS
Matt Hanson
Managing Editor, Core Tech

Matt is TechRadar's Managing Editor for Core Tech, looking after computing and mobile technology. Having written for a number of publications such as PC Plus, PC Format, T3 and Linux Format, there's no aspect of technology that Matt isn't passionate about, especially computing and PC gaming. He’s personally reviewed and used most of the laptops in our best laptops guide - and since joining TechRadar in 2014, he's reviewed over 250 laptops and computing accessories personally.

Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening