{"id":1991,"date":"2021-02-20T15:30:10","date_gmt":"2021-02-20T20:30:10","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=1991"},"modified":"2021-02-20T15:30:12","modified_gmt":"2021-02-20T20:30:12","slug":"vicious-panda-malware-that-uses-the-pandemic","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/vicious-panda-malware-that-uses-the-pandemic\/","title":{"rendered":"Vicious Panda &#8211; Malware that uses the pandemic"},"content":{"rendered":"\n<p>Like every time there is a news item of global interest, it is used by cybercriminals as bait to induce their victims to click on the links that serve as infection vectors for malware. In this case, as you can already deduce, the bait has been Coronavirus. The announcement was made public by Check Point and named it Vicious Panda and is especially aimed at the Mongolian public sector. The group to which the attack has been linked appears to be a Chinese group related to attacks on countries such as Ukraine, Russia and Belarus.<\/p>\n\n\n\n<p>The ultimate goal of this malware is to infect the system with a remote access Trojan. This Trojan, once installed on the victim&#8217;s computer, will give the attacker full access remotely, being able to access files, passwords, etc. that exist on the affected system.<\/p>\n\n\n\n<p>The computer infection process is carried out thanks to the vulnerabilities (CVE-2017-11882, CVE-2018-0798) existing in the Microsoft Word equation editor. To do this, an RTF file is sent to the victims of the Mongolian public sector that allegedly contains information on the subject of coronavirus.<\/p>\n\n\n\n<p>This file is specially designed by attackers to exploit the aforementioned vulnerabilities, so that, after exploiting the vulnerability, the initial malware payload is executed. This &#8216;payload&#8217; is responsible for creating a file called &#8216;intel.wll&#8217; in the directory, being a persistence technique that allows malware to run every time a Microsoft Word document is opened.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What this malware called Vicious Panda can cause to our computers<\/h2>\n\n\n\n<p>The system&#8217;s remote control module allows attackers to perform the following actions:<\/p>\n\n\n\n<p><strong><em>\u25b8Get a list of files and directories<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8Take screenshots<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8Create and delete directories<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8Download files<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8Move and delete files<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8Run new processes<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8Get a list of configured services<\/em><\/strong><\/p>\n\n\n\n<p>Many cybercriminals are carrying out campaigns of these types due to the popularity of the search for the Coronavirus, for this it must be borne in mind that you should not fall for these tricks and the best thing you can do with these emails is to ignore them.<\/p>\n\n\n\n<p>See also:<br><a href=\"https:\/\/truxgoservers.com\/blog\/potential-hoaxes-using-coronavirus-fake-news\/\">Potential Hoaxes Using Coronavirus Fake News<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/cybercriminals-are-targeting-health-institutions\/\">Cybercriminals are targeting health institutions<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Like every time there is a news item of global interest, it is used by cybercriminals as bait to induce their victims to click on the links that serve as infection vectors for malware. In this case, as you can already deduce, the bait has been Coronavirus. The announcement was made public by Check Point [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1992,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-1991","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Vicious Panda - Malware that uses the pandemic - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Many cybercriminals are carrying out false advertising campaigns about the Coronavirus and this is the case of Vicious Panda....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/vicious-panda-malware-that-uses-the-pandemic\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Vicious Panda - Malware that uses the pandemic - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Many cybercriminals are carrying out false advertising campaigns about the Coronavirus and this is the case of Vicious Panda....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/vicious-panda-malware-that-uses-the-pandemic\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-02-20T20:30:10+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-02-20T20:30:12+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/02\/Ciberseguridad-Covid-19.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"853\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vicious-panda-malware-that-uses-the-pandemic\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vicious-panda-malware-that-uses-the-pandemic\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Vicious Panda &#8211; Malware that uses the pandemic\",\"datePublished\":\"2021-02-20T20:30:10+00:00\",\"dateModified\":\"2021-02-20T20:30:12+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vicious-panda-malware-that-uses-the-pandemic\\\/\"},\"wordCount\":364,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vicious-panda-malware-that-uses-the-pandemic\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/02\\\/Ciberseguridad-Covid-19.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vicious-panda-malware-that-uses-the-pandemic\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vicious-panda-malware-that-uses-the-pandemic\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vicious-panda-malware-that-uses-the-pandemic\\\/\",\"name\":\"Vicious Panda - Malware that uses the pandemic - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vicious-panda-malware-that-uses-the-pandemic\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vicious-panda-malware-that-uses-the-pandemic\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/02\\\/Ciberseguridad-Covid-19.jpg\",\"datePublished\":\"2021-02-20T20:30:10+00:00\",\"dateModified\":\"2021-02-20T20:30:12+00:00\",\"description\":\"Many cybercriminals are carrying out false advertising campaigns about the Coronavirus and this is the case of Vicious Panda....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vicious-panda-malware-that-uses-the-pandemic\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vicious-panda-malware-that-uses-the-pandemic\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vicious-panda-malware-that-uses-the-pandemic\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/02\\\/Ciberseguridad-Covid-19.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/02\\\/Ciberseguridad-Covid-19.jpg\",\"width\":1280,\"height\":853},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/vicious-panda-malware-that-uses-the-pandemic\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Vicious Panda &#8211; Malware that uses the pandemic\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Vicious Panda - Malware that uses the pandemic - Truxgo Server Blog","description":"Many cybercriminals are carrying out false advertising campaigns about the Coronavirus and this is the case of Vicious Panda....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/vicious-panda-malware-that-uses-the-pandemic\/","og_locale":"es_MX","og_type":"article","og_title":"Vicious Panda - Malware that uses the pandemic - Truxgo Server Blog","og_description":"Many cybercriminals are carrying out false advertising campaigns about the Coronavirus and this is the case of Vicious Panda....","og_url":"https:\/\/truxgoservers.com\/blog\/vicious-panda-malware-that-uses-the-pandemic\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-02-20T20:30:10+00:00","article_modified_time":"2021-02-20T20:30:12+00:00","og_image":[{"width":1280,"height":853,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/02\/Ciberseguridad-Covid-19.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/vicious-panda-malware-that-uses-the-pandemic\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/vicious-panda-malware-that-uses-the-pandemic\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Vicious Panda &#8211; Malware that uses the pandemic","datePublished":"2021-02-20T20:30:10+00:00","dateModified":"2021-02-20T20:30:12+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/vicious-panda-malware-that-uses-the-pandemic\/"},"wordCount":364,"commentCount":1,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/vicious-panda-malware-that-uses-the-pandemic\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/02\/Ciberseguridad-Covid-19.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/vicious-panda-malware-that-uses-the-pandemic\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/vicious-panda-malware-that-uses-the-pandemic\/","url":"https:\/\/truxgoservers.com\/blog\/vicious-panda-malware-that-uses-the-pandemic\/","name":"Vicious Panda - Malware that uses the pandemic - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/vicious-panda-malware-that-uses-the-pandemic\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/vicious-panda-malware-that-uses-the-pandemic\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/02\/Ciberseguridad-Covid-19.jpg","datePublished":"2021-02-20T20:30:10+00:00","dateModified":"2021-02-20T20:30:12+00:00","description":"Many cybercriminals are carrying out false advertising campaigns about the Coronavirus and this is the case of Vicious Panda....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/vicious-panda-malware-that-uses-the-pandemic\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/vicious-panda-malware-that-uses-the-pandemic\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/vicious-panda-malware-that-uses-the-pandemic\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/02\/Ciberseguridad-Covid-19.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/02\/Ciberseguridad-Covid-19.jpg","width":1280,"height":853},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/vicious-panda-malware-that-uses-the-pandemic\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Vicious Panda &#8211; Malware that uses the pandemic"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/1991","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=1991"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/1991\/revisions"}],"predecessor-version":[{"id":2006,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/1991\/revisions\/2006"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/1992"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=1991"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=1991"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=1991"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}