Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Email Security

Google Sees Millions of COVID-19-Related Malicious Emails Daily

Over the past week, Google has observed more than 18 million malware and phishing emails related to COVID-19 being sent out every day.

Additionally, the Internet giant is seeing over 240 million COVID-19-related daily spam messages. On a daily basis, Gmail blocks 100 million phishing emails.

Over the past week, Google has observed more than 18 million malware and phishing emails related to COVID-19 being sent out every day.

Additionally, the Internet giant is seeing over 240 million COVID-19-related daily spam messages. On a daily basis, Gmail blocks 100 million phishing emails.

Last week, Microsoft said it saw around 60,000 daily phishing emails carrying COVID-19 lures, but that they represented less than 2% of the total phishing attempts.

Multiple threat actors have adopted the current COVID-19 pandemic as a theme for email attacks, in an attempt to trick users into revealing credentials, installing malware, or sending money to attacker-controlled accounts.

“The phishing attacks and scams we’re seeing use both fear and financial incentives to create urgency to try to prompt users to respond,” Google says.

Some of the attacks observed by the company attempt to impersonate authoritative government organizations like the World Health Organization (WHO) to ask for fraudulent donations or to distribute malware.

Other malicious emails target employees operating in a work-from-home setting, or attempt to phish small businesses by making reference to government stimulus packages and imitating government institutions.

Advertisement. Scroll to continue reading.

Google said it “put proactive monitoring in place for COVID-19-related malware and phishing,” while also noting that most of these threats are not new, but rather updated to fit the current trend.

“As soon as we identify a threat, we add it to the Safe Browsing API, which protects users in Chrome, Gmail, and all other integrated products. Safe Browsing helps protect over four billion devices every day by showing warnings to users when they attempt to navigate to dangerous sites or download dangerous files,” the Internet giant says.

Related: COVID-19 Lures Only a Fraction of Daily Phishing Emails

Related: Corporate Workers Warned of ‘COVID-19 Payment’ Emails Delivering Banking Trojan

Related: Syrian Hackers Target Mobile Users With COVID-19 Lures

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join security experts as they discuss ZTNA’s untapped potential to both reduce cyber risk and empower the business.

Register

Join Microsoft and Finite State for a webinar that will introduce a new strategy for securing the software supply chain.

Register

Expert Insights

Related Content

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Phishing

The easiest way for a cyber-attacker to gain access to sensitive data is by compromising an end user’s identity and credentials. Things get even...

Cloud Security

Cloud security researcher warns that stolen Microsoft signing key was more powerful and not limited to Outlook.com and Exchange Online.

Cybercrime

No one combatting cybercrime knows everything, but everyone in the battle has some intelligence to contribute to the larger knowledge base.

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...

Cloud Security

Microsoft and Proofpoint are warning organizations that use cloud services about a recent consent phishing attack that abused Microsoft’s ‘verified publisher’ status.

Malware & Threats

Threat actors are increasingly abusing Microsoft OneNote documents to deliver malware in both targeted and spray-and-pray campaigns.