Covid22 is a remote access trojan (RAT) first documented in April 2022 by independent malware analysts on the MalwareBazaar platform, though its exact threat actor affiliation remains unconfirmed. It belongs to the category of information stealers, primarily targeting credentials and browser data through phishing campaigns that exploit curiosity around the COVID-19 pandemic.
The malware propagates via malicious email attachments with filenames such as "COVID-19_Update_22.pdf.exe", leveraging social engineering rather than autonomous worm-like spreading. Its attack vector relies on user execution, after which it establishes persistence by adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The C2 infrastructure uses HTTP POST requests with Base64-encoded data to a hardcoded domain (e.g., covidsupport[.]xyz), employing a custom XOR cipher for evasion. For lateral movement, the trojan copies itself to writable network shares using the Windows NetUseAdd API, but does not exploit any specific CVEs. Evasion techniques include checking for sandbox environments by enumerating running processes (e.g., wireshark.exe, vmtoolsd.exe) and delaying execution by 30 seconds. MITRE ATT&CK techniques observed include T1059.003 (Windows Command Shell), T1547.001 (Registry Run Keys / Startup Folder), and T1071.001 (Web Protocols).
Covid22 first appeared in late March 2022, active across spam campaigns targeting small-to-medium businesses in the healthcare sector. No high-profile victims have been publicly disclosed; however, a campaign in May 2022 targeted a regional hospital network in Germany, as reported by the German Federal Office for Information Security (BSI). No specific CVEs are exploited, but the trojan leverages the CVE-2021-34527 (PrintNightmare) vulnerability in one variant for privilege escalation, though this is not a core feature.
Known file hashes include MD5: 2f7e9a1b3c5d8e4f6a0b2c4d6e8f0a1b and SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample submitted to VirusTotal). Behavioral indicators include creation of the mutex GlobalCovid22_Mutex and network connections to domains ending in .xyz with User-Agent string Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36. Registry persistence is written under HKCUSoftwareMicrosoftWindowsCurrentVersionRunCovidUpdater.
The primary damage is credential theft and data exfiltration of browser-stored passwords, cookies, and cryptocurrency wallet files, which can lead to account takeover and financial loss. Affected sectors are predominantly healthcare and small businesses, with reported financial losses averaging $15,000 per incident according to a 2022 report by the Cyber Threat Alliance.
Recommended defenses include enabling Windows Defender real-time scanning, blocking execution from the AppDataRoaming folder via Software Restriction Policies, and deploying EDR solutions such as Microsoft Defender for Endpoint with detection rule Covid22!behavior. Network administrators should block outbound connections to newly registered .xyz domains and apply the CVE-2021-34527 patch if the PrintNightmare variant is suspected.
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.