Microsoft Warns of Massive COVID-19 Themed Phishing Campaign That Lets Attackers Gain Remote Access

The Microsoft Security Intelligence team has detailed how the campaign is being used to remotely access systems with malicious Excel files.

Advertisement
By Jagmeet Singh | Updated: 20 May 2020 18:50 IST
Highlights
  • Microsoft Security Intelligence has revealed the campaign through tweets
  • Malicious emails pretend to be from John Hopkins Center
  • Microsoft has provided a sample case to show the scope of the campaign
Microsoft Warns of Massive COVID-19 Themed Phishing Campaign That Lets Attackers Gain Remote Access

Microsoft’s researchers have found NetSupport Manager is being used to gain remote access

Microsoft says a massive COVID-19 themed phishing campaign is underway, as a part of which attackers install the NetSupport Manager remote access tool to gain remote access. The new campaign, which was detected by the Microsoft Security Intelligence team, started on May 12. The malware payload comes through malicious Excel attachments that are being sent by the attackers via emails. Notably, this isn't the first time when cyber-attackers are using COVID-19 as an opportunity to hack people. Companies including Google have already warned about the increase in such phishing attacks.

Through a series of tweets, the Microsoft Security Intelligence team has detailed the ongoing phishing attacks. The team says that the campaign delivers the NetSupport Manager using emails with attachments containing malicious Excel 4.0 macros.

As per the details provided by the Microsoft team, the attack begins with emails that pretend to come from Johns Hopkins Center and show details about the active COVID-19 cases in the US. However, in reality, the emails include Excel files that once open, show a graphical representation of the coronavirus data. However, the files also include malicious Excel 4.0 macros that will prompt users to “Enable Content”. This begins the download and installation process of the NetSupport Manager client from a remote site.

Microsoft's researchers have found that emails pretend to come from John Hopkins Center carry malicious Excel files
Photo Credit: Twitter/ Microsoft Security Intelligence

Advertisement

 

“For several months now, we've been seeing a steady increase in the use of malicious Excel 4.0 macros in malware campaigns. In April, these Excel 4.0 campaigns jumped on the bandwagon and started using COVID-19 themed lures,” the team notes in one of its tweets.

Advertisement

Once the remote access tool is installed on a victim's system, the attackers can access and run commands remotely.

In a particular case, the Microsoft team has noticed that the NetSupport Manager was used to drop multiple components, including some executable files and establish connectivity with a C2 server to enable further commands from the attackers.

Advertisement

Pay attention to what you're downloading from emails
Users are recommended to avoid paying attention to random emails and verify email addresses from where they're receiving new emails before downloading the included attachments. Also, it is suggested to immediately change passwords if you find any odd behaviour on your system.


How are we staying sane during this Coronavirus lockdown? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement
Popular Mobile Brands
  1. Samsung Galaxy A26 Review
  2. Xiaomi Pad 7 Ultra With XRING 01 SoC and 12,000mAh Battery Launched
  3. OTT Releases of the Week: Truth or Trouble, Motorheads, and More
  4. Xiaomi Launches YU7 EV in China With 253 KMPH Claimed Top Speed
  5. Infinix GT 30 Pro 5G India Launch Date, Colours, Key Features Confirmed
  6. Lava Shark 5G With Unisoc T765 Chipset, 5,000mAh Battery Launched in India
  7. Jio Rolls Out Prepaid Gaming Plans With JioGames Cloud Subscription
  8. Realme GT 7T Roundup: All You Need to Know Ahead of Its Debut
  9. Tecno Pova Curve 5G India Launch Date Announced
  10. WhatsApp Rolls Out Voice Chat Feature With End-to-End Encryption
  1. Samsung Tri-Fold Smartphone Price Tipped to Exceed $3,000; Launch Timeline Leaked
  2. Indian Developer Underdogs Studios Reveals Gameplay for Mukti, Narrative Title Coming to PS5 and PC
  3. Xiaomi Watch S4 15th Anniversary Edition Unveiled With XRING T1 Chipset
  4. HSBC Launches Blockchain-Based Tokenised Deposit Service in Hong Kong
  5. Oppo A5x 5G With MediaTek Dimensity 6300 SoC, 6,000mAh Battery Launched in India: Price, Specifications
  6. Vercel Releases v0 AI Model for Web Application Development, Compatible with OpenAI API
  7. Infinix GT 30 Pro 5G India Launch Set for June 3; Colour Options, Key Features Revealed
  8. Reliance Jio Rolls Out Prepaid Gaming Plans With JioGames Cloud Access in India: Price, Benefits
  9. Landman Season 1 Now Available on JioHotstar: What You Need to Know About American Political Drama Series
  10. Fountain of Youth Now Streaming on Apple TV+: What You Need to Know About American Adventure Movie
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.