With the coronavirus (COVID-19) pandemic raging all over the globe, some malware authors have developed malware that destroys infected systems, either by wiping files or rewriting a computer's master boot record (MBR).
With help from the infosec community, ZDNet has identified at least five malware strains, some distributed in the wild, while others appear to have been created only as tests or jokes.
The common theme among all four samples is that they use a coronavirus-theme and they're geared towards destruction, rather than financial gain.
MBR-rewriting malware
Of the four malware samples found by security researchers this past month, the most advanced were the two samples that rewrote MBR sectors.
Some advanced technical knowledge was needed to create these strains as tinkering with a master boot record is no easy feat and could easily result in systems that didn't boot at all.
The first of the MBR-rewriters was discovered by a security researcher that goes by the name of MalwareHunterTeam, and detailed in a report from SonicWall this week. Using the name of COVID-19.exe, this malware infects a computer and has two infection stages.
In the first phase, it just shows an annoying window that users can't close because the malware has also disabled the Windows Task Manager.
While users attempt to deal with this window, the malware is silently rewriting the computer's master boot record behind their back. It then restarts the PC, and the new MBR kicks in, blocking users into a pre-boot screen.
Users can eventually regain access to their computers, but they'll need special apps that can be used to recover and rebuild the MBR to a working state.
But there was a second coronavirus-themed malware strain that re-wrote the MBR. This one is a far more convoluted malware operation.
It posed as the "CoronaVirus ransomware" but it was only a facade. The malware's primary function was to steal passwords from an infected host and then mimic ransomware to trick the user and mask its real purpose.
However, it wasn't ransomware either. It only posed as one. Once the data-stealing operations ended, the malware entered into a phase where it rewrote the MBR, and blocked users into a pre-boot message, preventing access to their PCs. With users seeing ransom notes and then not being able to access their PCs, the last thing users would thing to do is to check if someone exfiltrated passwords from their apps.
According to analysis from SentinelOne security researcher Vitali Kremez and Bleeping Computer, the malware also contained code to wipe files on the user's systems, but this didn't appear to be active in the version they analyzed.
Furthermore, this one was also spotted twice, with a second version discovered by G DATA malware researcher Karsten Hahn, two weeks later. This time, the malware kept the MBR-rewriting capabilities but replaced the data wiping feature with a functional screen-locker.
But security researchers have spotted more than coronavirus-themed MBR-rewriters. They also spotted two data wipers.
Both were discovered by MalwareHunterTeam.
The first was spotted back in February. It used a Chinese file name, and most likely targeted Chinese users, although we don't have information if it was distributed in the wild or was just a test.
The second was spotted yesterday, and this one was found uploaded on the VirusTotal portal by someone located in Italy.
MalwareHunterTeam described both strains as "poor wipers" because of the inefficient, error-prone, and time-consuming methods they used to erase files on infected systems. However, they worked, which made them dangerous if ever spread in the wild.
It might seem weird that some malware authors create destructive malware like this, but it's not the first time that this happened. For every financially-motivated malware strain that security researchers discover, there's also one that was created as a joke, just for the giggles. Something similar happened during the WannaCry ransomware outbreak in 2017, when days after the original WannaCry ransomware encrypted computers all over the world, there were countless of clones doing the same thing for no apparent reason.
Originally posted here:
There's now COVID-19 malware that will wipe your PC and rewrite your MBR - ZDNet
- Ludicrous: bitter row erupts over plan to replace windows at Notre Dame - The Guardian - January 3rd, 2025 [January 3rd, 2025]
- Driver Charged For Using Duct Tape As A Window Replacement - muskoka411.com - January 3rd, 2025 [January 3rd, 2025]
- Commercial vehicle driver charged for using duct tape as window replacement - CTV News Barrie - January 3rd, 2025 [January 3rd, 2025]
- Commercial Vehicle Driver Charged for Using Duct Tape as a Window Replacement - Bayshore Broadcasting News Centre - January 3rd, 2025 [January 3rd, 2025]
- Real Madrid Interested In Signing Toni Kroos Replacement In Summer Transfer Window - Sports Illustrated - January 3rd, 2025 [January 3rd, 2025]
- Six moves Chelsea should make during the 2025 January transfer window: Blues must move on the deadwood and find a replacement for unreliable Robert... - January 3rd, 2025 [January 3rd, 2025]
- CCG begins window replacement contract for Partick Housing Association - Scottish Construction Now - December 21st, 2024 [December 21st, 2024]
- Pella vs. Lowes Windows: What to know when buying the big brands - New York Post - November 29th, 2024 [November 29th, 2024]
- You can get massive tax credits for replacing your old windows here's how to collect - The Cool Down - November 29th, 2024 [November 29th, 2024]
- The 5 best window brands to level up your home in 2024 - New York Post - November 29th, 2024 [November 29th, 2024]
- Club searching for replacement as player set to join Southampton in January window - Sport Witness - November 29th, 2024 [November 29th, 2024]
- Boone County Courthouse windows leak after 35 years, replacements are on the way - cnhinews.com - November 12th, 2024 [November 12th, 2024]
- Walt's Window Repair & Screening in Coconut Creek Continues Legacy After 45 Years as Business Enters Second Generation of Family Ownership -... - October 28th, 2024 [October 28th, 2024]
- Video art installation in Philadelphia offers a window into 3 cities elsewhere in the world - KYW - October 28th, 2024 [October 28th, 2024]
- I tried replacing the Windows 11 desktop with a web app, and I'm very excited for the future - XDA Developers - October 28th, 2024 [October 28th, 2024]
- BTL Windows and Siding | Window Replacement - WGHP FOX8 Greensboro - October 9th, 2024 [October 9th, 2024]
- How Much Does Main Water Shut-Off Valve Replacement Cost In 2024? - Forbes - October 9th, 2024 [October 9th, 2024]
- Parking impacts: University Bookstore window replacement - Virginia Tech - September 29th, 2024 [September 29th, 2024]
- How much does skylight window installation cost in 2024? Materials, installation and other factors - USA TODAY - September 29th, 2024 [September 29th, 2024]
- Improve the Efficiency of Your Home with Renewal by Andersen's Replacement Window & Doors - ABC Action News Tampa Bay - September 20th, 2024 [September 20th, 2024]
- Robots replace human window washers on skyscrapers - Fox News - September 20th, 2024 [September 20th, 2024]
- Highrise window plunges 30 stories, hits car in San Francisco - NBC Bay Area - September 7th, 2024 [September 7th, 2024]
- Tenant in disbelief after discovering HOA's shortcut with window replacement: 'Odds are they didn't pull a permit' - The Cool Down - September 7th, 2024 [September 7th, 2024]
- Moving to Texas Statistics: Our 2024 Report - USA TODAY - August 25th, 2024 [August 25th, 2024]
- The Best Window Brands of August 2024 - MarketWatch - August 25th, 2024 [August 25th, 2024]
- 'I have until next week': Toronto condo owner facing $40,000 bill for new windows - CTV News Toronto - August 17th, 2024 [August 17th, 2024]
- New controversy at Notre Dame over stained glass replacement - Aleteia - January 13th, 2024 [January 13th, 2024]
- Pro vs DIY Window Replacement: Which Is Better for Your Home? - FINE Homes and Living - January 5th, 2024 [January 5th, 2024]
- How to replace your broken window - Otago Daily Times - January 5th, 2024 [January 5th, 2024]
- Shop New Windows & Doors | Pella of Naperville - March 24th, 2023 [March 24th, 2023]
- How Much Does Window Glass Replacement Cost? - Bob Vila - November 1st, 2022 [November 1st, 2022]
- Window Replacement - Home Window Replacement & Installation - Window Nation - September 30th, 2022 [September 30th, 2022]
- Best Replacement Window Companies Of September 2022 - September 30th, 2022 [September 30th, 2022]
- Three Brothers LLC Boise Announces That They Are Offering Peerless Local Window Installation Services - Digital Journal - September 30th, 2022 [September 30th, 2022]
- Kingston compensation for woman who waited more than two months for window repair - Surrey Comet - September 30th, 2022 [September 30th, 2022]
- What to know as Manitowoc County mulls property tax hike to help fund courthouse renovations expected to exceed $25M - Herald Times Reporter - September 30th, 2022 [September 30th, 2022]
- LG wants to replace Metro and other subway train windows with transparent OLED displays - Firstpost - September 30th, 2022 [September 30th, 2022]
- New Apodaca art installation showcases the talents of renowned glass artists - Western Carolina University News - September 30th, 2022 [September 30th, 2022]
- Jesus joins the Bristol Bus Boycott to replace Colston stained glass window - Bristol Live - September 30th, 2022 [September 30th, 2022]
- 5 Things to Know About Owning a Car in This Economy - theSkimm - September 30th, 2022 [September 30th, 2022]
- Amazon warehouse robots are getting closer to replacing human hands - Vox.com - September 30th, 2022 [September 30th, 2022]
- Avoid auto-installation of Windows Home when installing Windows - Hindu Wire - September 30th, 2022 [September 30th, 2022]
- Spotlight:Six factors that impact the cost of your home window replacement project - CambridgeToday - August 20th, 2022 [August 20th, 2022]
- How to Install a Window AC Unit - CNET - August 20th, 2022 [August 20th, 2022]
- Vandal smashes windows at three Vancouver businesses - The Columbian - August 20th, 2022 [August 20th, 2022]
- Report: Windows 11 22H2 update will be released on September 20 - Ars Technica - August 20th, 2022 [August 20th, 2022]
- Why the Bucs should replace Tom Brady with Lamar Jackson in 2023 - Bucs Wire - August 20th, 2022 [August 20th, 2022]
- Three more players expected to leave Brighton before the end of the summer transfer window - SussexWorld - August 20th, 2022 [August 20th, 2022]
- Hull firm's pride as installation rating puts it in top bracket for UK window work - Business Live - August 20th, 2022 [August 20th, 2022]
- Findochty windows: Councillors allow uPVC in conservation area - The Press & Journal - August 20th, 2022 [August 20th, 2022]
- Analysing all the strikers linked to Man Utd to replace Ronaldo: Morata, Pulisic, Felix, Gakpo and more under the microscope - Goal.com - August 20th, 2022 [August 20th, 2022]
- Fix Windows 11/10 Installation error 0x800F0955 - 0x20003 - TWCN Tech News - January 12th, 2022 [January 12th, 2022]
- Window and insulation rebates doubled in Clark County - The Reflector - January 12th, 2022 [January 12th, 2022]
- Narrative installation 'Lost in the Woods' taps into art, writing students' talents - Fredonia.edu - January 12th, 2022 [January 12th, 2022]
- Groove Music player updated and replaced with new Windows 11 Media Player for some - OnMSFT.com - January 12th, 2022 [January 12th, 2022]
- City, Hope Home Repair to part ways The Kansan - Newton Kansan - January 12th, 2022 [January 12th, 2022]
- Five players Sheffield Wednesday could sign in January transfer window to replace Theo Corbeanu - Yorkshire Live - January 12th, 2022 [January 12th, 2022]
- These two Bergen towns will hold special elections on school repairs costing over $20M - NorthJersey.com - January 12th, 2022 [January 12th, 2022]
- Automotive Replacement Glass Windshields Market to Witness Robust Expansion by 2029 | AGC Automotive Replacement Glass, Glass Doctor, Magna ... - January 12th, 2022 [January 12th, 2022]
- Army finally picks an optic for Next Generation Squad Weapon - DefenseNews.com - January 12th, 2022 [January 12th, 2022]
- Window Woman to appear on 'This Old House' - The Daily News of Newburyport - December 28th, 2021 [December 28th, 2021]
- Comment: Another year goes by and Apple still hasnt replaced iTunes on Windows with something better - 9to5Mac - December 28th, 2021 [December 28th, 2021]
- Knocking over a fan's beer and replacing it has become the hottest trend in pro sports - GolfDigest.com - December 28th, 2021 [December 28th, 2021]
- What the Army's Bradley replacement will look like may be decided in 2022 - ArmyTimes.com - December 28th, 2021 [December 28th, 2021]
- Microsoft's wins, fails, and WTF moments of 2021 - PCWorld - December 28th, 2021 [December 28th, 2021]
- Spurs can finally replace Toby with 90k-p/w "beast" who has "always been the leader" - opinion - MSN UK - December 28th, 2021 [December 28th, 2021]
- The biggest Arizona headlines of 2021, from recycling plant fire to COVID-19 to a partisan election review - The Arizona Republic - December 28th, 2021 [December 28th, 2021]
- Two And A Half Suggestions For A Manchin-Approved Build Back Better/Social Insurance Program - Forbes - December 28th, 2021 [December 28th, 2021]
- Rdiger's hopes for Real Madrid move placed on the back burner - AS English - December 28th, 2021 [December 28th, 2021]
- Replacement Glass Shortage Adding To Woes Of San Francisco Car Break-Ins Victims - CBS San Francisco - November 4th, 2021 [November 4th, 2021]
- Ask the Remodeler: Replace or refurbish? A look at old windows - The Boston Globe - November 4th, 2021 [November 4th, 2021]
- Thats The Wijnaldum Replacement Sorted - Pundit On Liverpool Target Youri Tielemans - Sports Illustrated - November 4th, 2021 [November 4th, 2021]
- Election Results 2021: Voters replace Westminster Mayor, City Council - The Westminster Window - November 4th, 2021 [November 4th, 2021]
- State Board of Regents approves additional $770000 for UI Stead Family Children's Hospital windows - UI The Daily Iowan - November 4th, 2021 [November 4th, 2021]
- Missing person posters replaced with pink balloons in celebration of Cleo Smiths return - WAtoday - November 4th, 2021 [November 4th, 2021]
- Liverpool have perfect 18m Roberto Firmino replacement ahead of January transfer window - Liverpool.com - November 4th, 2021 [November 4th, 2021]
- Racing Optics Offers Dealers and Installers Its WINDSHIELD DEFENSE KIT, Which Includes Its Multi-Layer Windshield Film System Which Provides Three... - November 4th, 2021 [November 4th, 2021]
- Skyscraper Window Washing Robots Are Here to Take Over One of Our Most Terrifying Jobs - Gizmodo - November 4th, 2021 [November 4th, 2021]
- 11 Worst Features of Windows 11 and How to Fix Them - Tom's Hardware - November 4th, 2021 [November 4th, 2021]
- Figge in Davenport makes repairs to its windows and to bridge community gaps - WHBF - OurQuadCities.com - November 4th, 2021 [November 4th, 2021]