Join our Newsletter — 33% off our NHI Course

What are the signs that a COVID-19 themed email campaign is malicious?

Common warning signs include generic but urgent language, sender addresses that do not match the supposed organisation, unexpected ZIP or Excel attachments, password protected files, macro prompts, and links to authentication pages that are unrelated to the claimed sender. Poor grammar does not make a message safe. Threat actors often rely on timing, not polish, to drive execution.

What makes a COVID-19 themed email campaign look malicious?

A COVID-19 themed campaign is usually malicious when the pandemic topic is being used as a delivery vehicle for social engineering rather than as a legitimate business message. The strongest indicators are mismatched sender identity, pressure to act quickly, and file or link patterns that do not fit the claimed organisation or purpose.

How attackers use the COVID-19 theme to make messages believable

The theme itself is not the warning sign. Criminals borrow current events to make urgent, relevant-looking messages more likely to be opened, especially when people expect health updates, policy changes, travel notices, benefits information, or workplace guidance. That means timing, context, and expected communication patterns matter more than whether the subject line sounds polished.

In practice, these campaigns often imitate a trusted employer, government agency, hospital, insurer, or charity, then attach a document or insert a link that pushes the recipient toward credential theft, malware delivery, or scam payment pages. A message can look professionally written and still be hostile if its delivery path or destination is inconsistent with the sender it claims to represent.

What to inspect before you trust the message

Start with the sender, the attachment type, and the destination of any link. A display name that looks familiar is not enough if the underlying address is off-domain or subtly altered. Likewise, ZIP archives, Excel files, password-protected documents, and macro-enabled attachments are common delivery choices because they can evade simple filters and encourage the recipient to enable content.

Links deserve the same scrutiny. A message that claims to come from one organisation but sends you to a generic sign-in page, a poorly matched domain, or an unexpected file host should be treated as suspicious. If the page is asking for credentials, payment, or MFA revalidation in a context that does not make sense for the sender, that is a strong indicator of abuse.

Poor grammar, odd formatting, or a few spelling mistakes may still appear in malicious messages, but they are not reliable indicators. Many campaigns are now good enough to pass a casual visual check, so verification has to focus on identity, destination, and requested action rather than tone alone.

Risk and Threat Considerations

These campaigns are dangerous because they exploit a high-trust, high-urgency topic to bypass normal scepticism. The operational risk is that users may open payloads or enter credentials into spoofed pages before they stop to validate the sender or destination.

Failure mechanism: The attacker relies on a believable health-related pretext to trigger fast execution, then uses attachment-based malware, credential harvesting, or redirect chains to turn attention into compromise.

Impact: The result can be account takeover, endpoint infection, payment fraud, or a broader phishing foothold that is reused for lateral movement or further social engineering.

Practitioner Guidance

What to verify: Train users and analysts to verify the actual sender domain, the real URL behind any link, and whether the requested action matches an expected business process. If a COVID-19 message asks for credentials, file opening, or urgent action outside a known workflow, treat it as suspicious until independently confirmed.

Common mistake: Do not use tone quality as the deciding factor. Well-written messages can be malicious, and legitimate notices can be poorly written. The better test is whether the message’s identity, content, and destination align with how that organisation normally communicates.

Practitioner takeaway: For theme-based phishing, context is the lure, but the decisive signal is mismatch, between claimed sender, requested action, and actual destination.