In the last couple of months, multiple reports of hackers misusing COVID-19 global pandemic to prey on naive users to steal financial credentials and now in the latest development, cybercriminals have developed a malicious Coronavirus software-laced Coronavirus tracking Android app. The COVID19 Tracker app is available for download on the website with the same name. If any user arrives at the site, he/she will be asked to download the Android app for the heat map. In addition to country-wise figures of COVID-19 outbreaks, recoveries, and deaths, it also provides details on the spread of the pandemic. Cyber security firm SonicWall warns users against ‘opportunist’ hackers.
Once the app is installed, the Coronavirus app, which houses ransomware ‘ CovidLock ‘ takes complete possession of the mobile handset and prevents the user from opening the screen lock.
“CovidLock utilizes tactics to restrict the victim users access to their mobile handset by forcing a change in the password used to unlock the phone. This is often regarded as a screen-lock attack and was previously used on Android ransomware. The CovidLock demands from the victims $100 ransom in bitcoins and, if they don’t oblige within 48 hours, alerts them to immediately delete all contacts, images, photos, messages and all other personal details from the phone. It also threatens to leak user IDs and passwords of social media accounts on public online platforms.
There’s no news on how many of them fallen victim to the CovidLock malware. To stop getting trapped, users are urged not to not to install the Android app from the third-party app store or from unknown or unfamiliar websites. Please download apps from the official Google store.
Here’s how to secure your phones and computers from ransomware, malware, trojan
1) If you have an Android smartphone or iOS-based iPhone or Windows-powered PC or a Mac machine, always update your devices with the latest software/apps. Google, Microsoft, and Apple send firmware regularly — especially security patches monthly or priority basis — when they identify threats. So, make sure you’re running the new software/apps.
2) This goes without mentioning that you should never access any illegal or shady websites and also recommended to see whether it has encrypted ‘https’ or just ‘http’. If it has the latter, just kill the link and start initiate anti-virus scanning on your devices.
3) Never access emails or SMS messages and click on URL links send by an unknown user.
4) Another safe idea is to install a premium Antivirus software/app that provides 24×7 security. They are equipped to easily spot threats and risks quickly if you unknowingly visit a shady website.
5) Never install update applications or software from unfamiliar publishers
6) As said before always download applications from Google Play or Apple App Store or Windows Store only. Never install from any third-party app store.