In all cases, the image files contain a version of the Remcos Remote Access Trojan (RAT) which allows the attackers to gain complete control over any machine their malware infects.
Microsoft identified three separate campaigns including:
Tanmay Ganacharya is the Director of Security Research in Microsoft's Threat Protection division.
Tanmay had this to say about the recent discovery:
"The main thing that we really wanted to call out, and why it caught our attention, is because of the COVID-19 lures and also because of the slightly different techniques we found and the type of attachments they are sending. They're using ISO files, which is not super common. It's not like this is the first time we have ever seen it, but it is also not like extremely common for attackers to do this."
It goes without saying that if you, or one of your employees, gets an email like any of those described above, don't run the attached files, and stay on your guard. We're almost certain to see many more attacks like these before the crisis is behind us.