The Wuhan virus is spreading rapidly around the world. Various tools to help people prevent and understand it are everywhere on the Internet and in app stores. People are also accustomed to obtaining relevant information from the Internet, but in this period of uncertainty and the desire for information, unscrupulous people are even more excited. A foreign network security company discovered that an application called “COVID19 Tracker” is actually used for extortion by using the name of Wuhan pneumonia. Everyone should be careful!

Ransomware application “COVID19 Tracker” disguised as a Wuhan virus-related application appears
Cyber Security Company DomainTools Researchers Chad Anderson and Tarik Saleh recently said that a ransomware application “COVID19 Tracker” disguised as a Wuhan pneumonia tracker has emerged. This application is mainly designed for the Android operating system. Whenever you search on the Internet, it will appear in the search results. Since Google Play has recently tightened control on related applications, you will enter the website after clicking it.

This website reminds visitors that since they need to obtain the number of confirmed cases of Wuhan pneumonia based on real-time GPS positioning, it will guide users to download an application and activate accurate reporting for the best experience. When opened, the app actually asks for permission to lock the screen so it can sound an alert when a patient is near, and it also asks for permission to monitor activity on an Android phone. Once you allow these permission requests unsuspectingly, a ransomware virus called “CovidLock” will be launched, and a ransom demand message as shown below will be displayed on the screen. Basically, users are required to pay $100 in Bitcoin within 48 hours (as the original text reads) to obtain an unlocking key, otherwise all content including contacts, photos, and videos will be deleted, and all social platform accounts will be publicly leaked:

DomainTools is currently monitoring hackers’ Bitcoin wallets and their activities, the company told foreign media Business Insider, so far no one seems to have paid the ransom to the hackers, but it is still unknown how many people have actually downloaded the app. This is not the first case of fraud in the name of Wuhan pneumonia. Last week, other network security researchers also discovered several fake tracker maps that, when opened, would infect users with malware. It is recommended that if you need to obtain relevant information, please obtain it from well-known and credible sources such as government agencies, research institutions, and authoritative individuals. If you need to download an application, be sure to download it from the normal process channel of the Google Play Store to reduce the risk of malicious attacks.
◎Data source:Business Insider
Source: KOCPC Chinese