Categories: SecurityWorkspace

US Tax Spam Spreads Zeus Trojan

Zeus is down off malware’s Mount Olympus and infecting PCs yet again, this time using a tax scam being spammed out by attackers as bait.

Using the US’ 15 October tax filing extension deadline as a ruse, the malware has been up to its old tricks, targeting banking and other user information. The spam typically comes with the subject lines “LAST NOTICE: Your Federal Tax Payment has been rejected in system” or “Your Tax Payment ID: 0103778341 has been rejected. Urgent Report information.”

According to researchers at Cisco Systems, the spam campaign at one point on 15 October accounted for more than one-third of all spam on the web.

Keylogger installed

“There is a link in the email that, on its surface, appears to link to the EFTPS [Electronic Federal Tax Payment System] website,” explained Solera Networks chief technology officer Joe Levy. “However, when the user clicks on the link they actually get redirected several times to various malware sites which attempt to download payloads specific to the user’s environment.”

Victims end up getting infected with Zeus v2. The Zeus Trojan has been the centre of some media attention lately due to the arrests of dozens of people around the world recently on cyber-crime charges. Popular among attackers because of its effectiveness, Zeus remains in widespread use in the cyber-underground, security researchers have said.

The latest attack came from domains registered in Russia, and came in two waves. After dropping off on the night of Thursday, 14 October, it spiked at around 34 percent of all spam at 15:00 hours UT on Friday. According to Cisco Senior Security Researcher Henry Stern, the spam run appears to be done, and whatever botnet was involved has probably moved on to something new.

In addition to Zeus, a keylogger was installed to track keystrokes on an infected system and send information to cyber-criminals. When users log on to the legitimate EFTPS website, the information transmitted to the attackers via the keylogger can range from bank account numbers to the name, phone number and address of a business.

“The timing of the attack seems to correspond with business tax filing season,” Levy added. “This makes it particularly targeted at small and medium businesses.”

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Share
Published by
Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

Craig Wright Sentenced For Contempt Of Court

Suspended prison sentence for Craig Wright for “flagrant breach” of court order, after his false…

2 days ago

El Salvador To Sell Or Discontinue Bitcoin Wallet, After IMF Deal

Cash-strapped south American country agrees to sell or discontinue its national Bitcoin wallet after signing…

2 days ago

UK’s ICO Labels Google ‘Irresponsible’ For Tracking Change

Google's change will allow advertisers to track customers' digital “fingerprints”, but UK data protection watchdog…

2 days ago

EU Publishes iOS Interoperability Plans

European Commission publishes preliminary instructions to Apple on how to open up iOS to rivals,…

3 days ago

Momeni Convicted In Bob Lee Murder

San Francisco jury finds Nima Momeni guilty of second-degree murder of Cash App founder Bob…

3 days ago