Close Menu
  • Home
  • News
  • Tech Jungle
  • RAWRMag
  • BIZnest
  • Brands
  • About
    • BE PART OF THE LIONHEARTV FAMILY!
    • THE PRIDE
    • ADVERTISE AT LIONHEARTV
What's Hot

Henry Cavill and Jake Gyllenhaal Lead ‘In The Grey’ as CreaZion Studios International Brings Film to PH Cinemas May 13

April 9, 2026

“Benefits go straight to my phone”: Caloocan seniors and solo parents now receive aid through GCash

April 9, 2026

Xyriel Manabat vows action vs TNVS driver over alleged harassment

April 9, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube TikTok
LionhearTVLionhearTV
  • Home
  • News
  • Tech Jungle
  • RAWRMag
  • BIZnest
  • Brands
  • About
    • BE PART OF THE LIONHEARTV FAMILY!
    • THE PRIDE
    • ADVERTISE AT LIONHEARTV
LionhearTVLionhearTV
Home»Technology»Palo Alto Networks: Studying How Cybercriminals Prey on the COVID-19 Pandemic
Technology

Palo Alto Networks: Studying How Cybercriminals Prey on the COVID-19 Pandemic

Lion's DenBy Lion's DenApril 29, 2020No Comments4 Mins Read
Share
Facebook Twitter Reddit Pinterest Email

Philippines, Metro Manila – 29 April 2020 – With the spread of the coronavirus worldwide, interest is high in related topics. Accordingly, Unit 42 researchers found an immense increase in Coronavirus-related Google searches and URLs viewed since the beginning of February.

Cybercriminals are looking to profit from such trending topics, disregarding ethical concerns, and in this particular case preying on the misfortunes of billions.

To protect customers of Palo Alto Networks, Unit 42 researchers monitor user interest in trending topics and newly registered domain names related to these topics, as miscreants often leverage them for malicious campaigns.

Using Google Trends and our traffic logs, we observed a steep increase in user interest of topics related to Coronavirus, with prominent peaks at the end of January, the end of February, and the middle of March 2020.

Accompanying the growth in user interest, we observed a 656% increase in the average daily Coronavirus-related domain name registrations from February to March. In this timeframe, we witness a 569% growth in malicious registrations, including malware and phishing; and a 788% growth in “high-risk” registrations, including scams, unauthorized coin mining, and domains that have evidence of association with malicious URLs within the domain or utilization of bulletproof hosting.

As of the end of March, we identified 116,357 Coronavirus-related newly registered domain names. Out of these, 2,022 are malicious and 40,261 are “high-risk”.

We analyze these domains by clustering them based on their Whois information, DNS records and screenshots (collected by our automated crawlers) to detect registration campaigns. We found that while many domains are registered to be resold for a profit, a significant fraction of them are used for both well-known malicious activities as well as for fraudulent shops selling items in short supply.

The traditional malice abusing Coronavirus trends includes domains hosting malware, phishing sites, fraudulent sites, malvertising, cryptomining, and Black Hat Search Engine Optimization (SEO) for improving search rankings of unethical websites. Interestingly, although many webshops that use newly registered domains try to scam users, we detected an especially unethical cluster of domains capitalizing on users’ fear of Coronavirus to further frighten them into buying their products. Moreover, we discovered a group of Coronavirus-themed domains, which now serve parked pages with high-risk JavaScript that may at anytime start redirecting users to malicious content.

Conclusion

Unfortunately, there will always be cybercriminals who will attempt to victimize people during local, national, and world events when their fears are elevated. We have observed this same type of behavior time and time again when calamitous events occur, cybercriminals start to circle for victims. Sadly, we do not expect this exploitative type of behavior to go away anytime soon.

People should be highly skeptical of any emails or newly-registered websites with COVID-19 themes, whether they claim to have information, a testing kit, or a cure. Special care should be taken to examine domain names for legitimacy and security, such as ensuring it is the legitimate domain (google[.]com vs g00gle[.]com), and that there is a lock icon to the left-hand side of the browser’s URL bar, ensuring a valid HTTPS connection.

Similar care should be taken with any COVID-19 themed emails – a look at the sender’s email address often reveals the content is likely not legitimate, as it’s either unknown to the recipient, mis-spelled, or suspiciously long with random seeming characters.

To protect users from cybercriminals, Palo Alto Networks best practice recommendation for URL Filtering is to block access to the Newly Registered Domain category. However if you cannot block access to the Newly Registered Domains category, then our recommendation would be to enforce SSL decryption to these URLs for increased visibility, to block users from downloading risky file types such as PowerShells and executables, to apply a much stricter Threat Prevention policy, and increase logging when accessing Newly Registered Domains. We also recommend DNS-layer protection, as we know over 80% of malware uses DNS to establish C2.

Due to the suddenness of the coronavirus outbreak, many employees are self-isolating and working from home. While organizations have always provided secure access to their employees via VPN connections, the enormous amount of employees requiring secure access is unprecedented and requires additional resources and capacity.

Palo Alto Networks offers Prisma Access, a cloud-delivered secure access service edge (SASE) platform that provides consistent policy enforcement and security for remote offices and mobile users, and will scale up and down as business demands evolve.

To learn more about how Palo Alto Networks can help remote employees, please see our resources here and check out Nir Zuk’s webcast on how to enable business continuity.

Comments

COVID-19 pandemic Cybercriminals Dominguez PR Palo Alto Networks PowerShells Unit 42
Share. Facebook Twitter Pinterest LinkedIn Reddit Email
Previous ArticleANC launches TV special and new show tackling ‘New Normal’ in the Philippines
Next Article ‘Cutting class ako dati sa comp class eh!’ Kim Chiu has a hard time editing her Vlogs
Lion's Den
  • Website
  • Facebook
  • X (Twitter)
  • Instagram

LionhearTV has always believed in what the everyday reader can contribute, and has always been open to receiving input, help, or leads on stories. Readers are always encouraged to drop us their thoughts either by either by leaving a comment on a post, or contact us directly – email us at lionheartvnet@gmail.com.

Related Posts

Changan showcases Eado Plus in Mandaluyong, redefining value for first-time car buyers

April 7, 2026

Nubia Neo 5 Series grand launch transforms SM Megamall into an immersive NEOverse

April 7, 2026

Castrol ignites motorcycle passion at InsideRacing 20th Bike Festival in Manila

March 28, 2026

HONOR X8d launch lights up Clubhouse BGC with style and innovation

March 28, 2026
Add A Comment

Comments are closed.

Find us on Facebook
Blogmeter.Top



Trending

LionhearTV continues to grow: Strengthening BIZNest, Tech Jungle, and RAWRTrip for 2026

February 14, 2026

15 Adored PH Celebrity Loveteams That Eventually Parted Ways

February 2, 2026

25 Best Teleseryes of 2025

January 14, 2026

GMA Pictures rolls out ambitious 2026 film slate, highlights animated features and major industry collaborations

January 7, 2026

Invited but silent: Celebrities, Influencers face backlash for not promoting MMFF 2025 films

January 3, 2026
Showbiz News

Xyriel Manabat vows action vs TNVS driver over alleged harassment

April 9, 2026

Dustin Yu, Bianca De Vera spark romance rumors with sweet farm photos

April 9, 2026

Nadine Lustre condemns alleged dove cruelty in Malabon church incident

April 8, 2026

PH bet Louis Jocson-Zabala heads to Thailand for Mr. Bear International 2026

April 8, 2026

Belle Mariano on online bashing: ‘I feel like never-ending naman ‘yan’

April 8, 2026
Most Viewed

Henry Cavill and Jake Gyllenhaal Lead ‘In The Grey’ as CreaZion Studios International Brings Film to PH Cinemas May 13

April 9, 2026

“Benefits go straight to my phone”: Caloocan seniors and solo parents now receive aid through GCash

April 9, 2026

Xyriel Manabat vows action vs TNVS driver over alleged harassment

April 9, 2026

BINI Makes Historic Debut at Coachella This Saturday (April 11 Pht)

April 9, 2026

Enduring Tongues Expands Indigenous Language Learning Access to Over 7,000 Community Members in Aklan

April 9, 2026
eMVP Digital is an online empire that useful pieces of information and a resource for a daily dose of entertainment in all forms. It produces LionhearTV.net, Dailypedia.net, RAWR Awards, RAWRMag, DailyPIPOL, and Broken Lion. These platforms have a highly-engaged audience per month, which varies from ages and sexes.



Blogmeter.Top
© 2026 LionhearTV.net.
  • Home
  • News
  • Tech Jungle
  • RAWRMag
  • BIZnest
  • Brands
  • About
    • BE PART OF THE LIONHEARTV FAMILY!
    • THE PRIDE
    • ADVERTISE AT LIONHEARTV

Type above and press Enter to search. Press Esc to cancel.