Exploiting COVID-19: how threat actors hijacked a pandemic
Image Description
Common Information
Type Value
UUID 1f8e1cdb-cda5-434f-b56e-0a806f1c9802
Fingerprint e49c96297c67c7f0254bf7f5a95b9e4b7107d1fbb550a9fc1b2d04b1190a57eb
Analysis status DONE
Considered CTI value 2
Text language
Published Sept. 19, 2022, 7:35 p.m.
Added to db April 16, 2024, 6:48 p.m.
Last updated Aug. 30, 2024, 11:59 p.m.
Headline Exploiting COVID-19: how threat actors hijacked a pandemic
Title Exploiting COVID-19: how threat actors hijacked a pandemic
Detected Hints/Tags/Attributes 160/4/34
Attributes
Details Type #Events CTI Value
Details CVE 63
cve-2017-8570
Details Domain 202
proofpoint.com
Details Domain 247
www.virusbulletin.com
Details Domain 4
careers.who.int
Details Domain 3
castodia.awsapps.com
Details Domain 13
www.who.int
Details Domain 10
www.cdc.gov
Details Domain 3
www.instituteforgovernment.org.uk
Details Domain 66
www.washingtonpost.com
Details Domain 370
www.proofpoint.com
Details Domain 124
www.nytimes.com
Details Email 3
dblackford@proofpoint.com
Details Email 3
slarson@proofpoint.com
Details Email 3
no-reply@castodia.awsapps.com
Details File 4
coronavirus_disease_covid-19__461657952561561.doc
Details File 3
covid19.html
Details File 3
korea-aligned-ta406-steals-scams-spies.pdf
Details File 3
mask-mandate-travel-transit.html
Details Microsoft Patch Numbers 4
KB4524147
Details Threat Actor Identifier - APT 181
APT33
Details Threat Actor Identifier - APT 665
APT29
Details Threat Actor Identifier - FIN 377
FIN7
Details Url 3
https://www.who.int/director-general/speeches/detail/who-director-general-s-opening-remarks-at-the-
Details Url 3
https://www.cdc.gov
Details Url 3
https://www.instituteforgovernment.org.uk/charts/uk-government-coronavirus-lockdowns.
Details Url 3
https://www.washingtonpost.com/business/2020/05/08/april-2020-jobs-report/.
Details Url 3
https://www.proofpoint.com/us/blog
Details Url 3
https://www.proofpoint.com/sites/default/files/threat-reports/pfpt-us-tr-threat-insight-paper-triple-threat-n-
Details Url 3
https://www.proofpoint.com/us/blog/threat-insight/chinese-apt-ta413-resumes-targeting-tibet-
Details Url 3
https://www.proofpoint.com/us/threat-insight/post/threat-actor-profile-ta407-silent-librarian.
Details Url 4
https://www.who.int
Details Url 3
https://www.nytimes.com/2022/04/19/business/mask-mandate-travel-transit.html
Details Url 3
https://www.proofpoint.com/us/blog/threat-insight/university-targeted-credential-
Details Url 3
https://www.proofpoint.com/us/blog/threat-insight/new-threat-actor-spoofs-