So cyber criminals are now creating a fake website, supposedly an anti-virus software. Instead what you're going to get is a
BlackNET RAT, which has the ability to:
• Deploying DDOS attacks
• Taking screenshots
• Stealing Firefox cookies
• Stealing saved passwords
• Implementing a keylogger
• Executing scripts
• Stealing Bitcoin wallets
Actual image of the fake site
Website:
https://corona-antivirus.com/
Download link:
http://antivirus-covid19.site/update.exe
Although as of now the download link is not working, but I'm sure those bad actors are going to relaunched it very soon and probably patching things up to that it will be hard to detect by AV. Now that most are working from home, just be very careful. They even added a bitcoin donation address. So far none has fallen for this and try to donate on that address.
Bitcoin Address: 15tvkwqxRw1rXPBsbbh3jUSNYkGg123fY7
A detailed technical explanation here:
https://blog.malwarebytes.com/threat-analysis/2020/03/fake-corona-antivirus-distributes-blacknet-remote-administration-tool/