If you have cybersecurity concerns or are experiencing an incident, IBM X-Force IRIS is here to help. Contact us. US hotline 1-888-241-9812; Global hotline (+001) 312-212-8034

Global events such as the novel coronavirus (COVID-19) make all of us attractive targets for cybercriminals. Whether it’s phishing emails or new targeted scams, these tactics are meant to take advantage of citizens who are understandably concerned about their health and safety during this challenging time.

COVID-19 email exploits can deliver damaging ransomware and other dangerous cyberthreats. X-Force Incident Response and Intelligence Services (IRIS) has decades of experience responding to these kinds of attacks. At the same time, this is a developing situation. We must remain vigilant and be on the lookout for criminals using scare tactics as a lure to encourage us to open malicious emails, potentially compromising our network security with malware that can steal our browsing history, IDs, passwords and other personal information.

We remain committed to keeping clients safe during this global event. To that end, we have created a consolidated X-Force Exchange Collection of known threat actors and how they’re exploiting COVID-19. It’s important you take a few moments and familiarize yourself with the basic recommendations in the collection. You should also be aware of the specific, known cyber activity related to COVID-19. This information is detailed in the links on the right side of the page under “Linked Collections.”

X-Force will update this collection with additional information as it becomes available. Please bookmark this URL and check back regularly for the latest threat actor information.

We are also offering public access to the X-Force IRIS COVID-19 Threat Intelligence Enclave brought to you by TruSTAR. TruSTAR combines X-Force IRIS Intelligence with a broad ecosystem intelligence, and the enclave makes urgent COVID-19 information more accessible, helping keep all of us more protected. The TruSTAR platform is available for 90 days at no-cost, beginning March 20, 2020.

Recommendations for our clients:

  • Security always starts with the basics. Ensure your systems are patched and IDS/IPS signatures and associated files are up to date. Attackers rely heavily on unpatched and out-of-date network configurations. Learn more about larger cyberthreat trends by downloading the X-Force Threat Intelligence Index 2020.
  • Access and share threat intelligence about COVID-19 threats at no charge for 90 days by joining the X-Force IRIS COVID-19 Threat Intelligence Enclave brought to you by TruSTAR. Learn more about other IRIS intel solutions here.
  • Keep applications and operating systems running at the current released patch level. Check X-Force Exchange for the latest vulnerabilities tracked by X-Force Red.
  • The Quad9 platform — available at no cost — can also help clients detect and block spoofed domains.
  • Consider using this time as an opportunity to test your own cyber resilience plan. A well-tested plan can help you reduce downtime and limit financial and reputational impact. Learn more about how IBM Security X-Force’s threat intelligence and incident response services can help you develop and test a robust plan to fortify your cyber resilience.
Register for the webinar to learn how to stay safe during COVID-19 uncertainty

More from Threat Intelligence

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

FYSA – Adobe Cold Fusion Path Traversal Vulnerability

2 min read - Summary Adobe has released a security bulletin (APSB24-107) addressing an arbitrary file system read vulnerability in ColdFusion, a web application server. The vulnerability, identified as CVE-2024-53961, can be exploited to read arbitrary files on the system, potentially leading to unauthorized access and data exposure. Threat Topography Threat Type: Arbitrary File System Read Industries Impacted: Technology, Software, and Web Development Geolocation: Global Environment Impact: Web servers running ColdFusion 2021 and 2023 are vulnerable Overview X-Force Incident Command is monitoring the disclosure…

Strela Stealer: Today’s invoice is tomorrow’s phish

12 min read - As of November 2024, IBM X-Force has tracked ongoing Hive0145 campaigns delivering Strela Stealer malware to victims throughout Europe - primarily Spain, Germany and Ukraine. The phishing emails used in these campaigns are real invoice notifications, which have been stolen through previously exfiltrated email credentials. Strela Stealer is designed to extract user credentials stored in Microsoft Outlook and Mozilla Thunderbird. During the past 18 months, the group tested various techniques to enhance its operation's effectiveness. Hive0145 is likely to be…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today