CoronaLocker Trojan
CoronaLocker is a newly observed trojan apparently designed to inconvenience users instead of causing damage.
Summary
CoronaLocker is a newly observed trojan apparently designed to inconvenience users instead of causing damage.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how CoronaLocker is delivered, although there are unconfirmed reports it is distributed disguised as hacking tools via third-party hosting sites.
Once installed, CoronaLocker will alter registry keys in order to disable common user interfaces including the Windows Start menu and the Run command. It then reboots the affected system, displaying a lock screen to the user and demanding a ransom. It will also use Window's speech synthesis function to repeat the phrase "corona virus".
Despite claiming to encrypt files, there is no evidence CoronaLocker alters user files in any way.
Remediation steps
| Type | Step |
|---|---|
|
CoronaLocker's lock screen can be bypassed by typing "vb" into the dialogue box. To re-enable registry editing, run the following command as an administrator in Command Prompt: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System” /t Reg_dword /v DisableRegistryTools /f /d 0 To prevent and detect a trojan infection, NHS Digital advises that:
Please note that NCSC maintains guidance for securely configuring a wide range of end user device (EUD) platforms. For further details refer to their end user device security guidance pages. |
Indicators of compromise
Last edited: 29 June 2021 12:01 pm