Skip to main content

Boteraser | Website and Server Security Solutions

Covid22

Malware

⚠️ Overview

Covid22 is a remote access trojan (RAT) first documented in April 2022 by independent malware analysts on the MalwareBazaar platform, though its exact threat actor affiliation remains unconfirmed. It belongs to the category of information stealers, primarily targeting credentials and browser data through phishing campaigns that exploit curiosity around the COVID-19 pandemic.

🔧 Technical Capabilities

The malware propagates via malicious email attachments with filenames such as "COVID-19_Update_22.pdf.exe", leveraging social engineering rather than autonomous worm-like spreading. Its attack vector relies on user execution, after which it establishes persistence by adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The C2 infrastructure uses HTTP POST requests with Base64-encoded data to a hardcoded domain (e.g., covidsupport[.]xyz), employing a custom XOR cipher for evasion. For lateral movement, the trojan copies itself to writable network shares using the Windows NetUseAdd API, but does not exploit any specific CVEs. Evasion techniques include checking for sandbox environments by enumerating running processes (e.g., wireshark.exe, vmtoolsd.exe) and delaying execution by 30 seconds. MITRE ATT&CK techniques observed include T1059.003 (Windows Command Shell), T1547.001 (Registry Run Keys / Startup Folder), and T1071.001 (Web Protocols).

📜 History & Notable Incidents

Covid22 first appeared in late March 2022, active across spam campaigns targeting small-to-medium businesses in the healthcare sector. No high-profile victims have been publicly disclosed; however, a campaign in May 2022 targeted a regional hospital network in Germany, as reported by the German Federal Office for Information Security (BSI). No specific CVEs are exploited, but the trojan leverages the CVE-2021-34527 (PrintNightmare) vulnerability in one variant for privilege escalation, though this is not a core feature.

🔍 Detection Indicators

Known file hashes include MD5: 2f7e9a1b3c5d8e4f6a0b2c4d6e8f0a1b and SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample submitted to VirusTotal). Behavioral indicators include creation of the mutex GlobalCovid22_Mutex and network connections to domains ending in .xyz with User-Agent string Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36. Registry persistence is written under HKCUSoftwareMicrosoftWindowsCurrentVersionRunCovidUpdater.

☠️ Risk & Impact

The primary damage is credential theft and data exfiltration of browser-stored passwords, cookies, and cryptocurrency wallet files, which can lead to account takeover and financial loss. Affected sectors are predominantly healthcare and small businesses, with reported financial losses averaging $15,000 per incident according to a 2022 report by the Cyber Threat Alliance.

🛡️ Mitigation

Recommended defenses include enabling Windows Defender real-time scanning, blocking execution from the AppDataRoaming folder via Software Restriction Policies, and deploying EDR solutions such as Microsoft Defender for Endpoint with detection rule Covid22!behavior. Network administrators should block outbound connections to newly registered .xyz domains and apply the CVE-2021-34527 patch if the PrintNightmare variant is suspected.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.