27 Mar 2010
Security experts are warning of a flood of spam emails masquerading as US tax documents in an attempt to spread the ZeuS malware.
Sans researcher Kevin Liston reported that the organisation had received several reports of unsolicited email claiming to come from the US Internal Revenue Service (IRS).
The emails claim that the recipient has 'under-reported income' on their tax statements, and urges them to download and run a linked file. The file is an executable which infects the user with the ZeuS malware.
The technique is not new. Citizens in the US and the UK were targeted by social engineering malware attacks last year purporting to be documents from tax authorities.
The IRS does not send official notifications via email, and advises people to avoid any messages claiming to be from the agency.
The ZeuS malware allows an attacker to locally edit HTML files on the victim's system to turn benign web pages into phishing sites and harvest credentials without the victim's knowledge.
The security community has begun tracking ZeuS, and has adopted a new strategy of notifying ISPs of the illegal activity and having the servers hosting the botnet shut down at the provider level.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Our client who are a large Pharmaceutical Company are...
IT Support Engineer (CCNA/CCIE) My client is a leading...
Company Information Atos is an international information...
Job Title Presales Consultant / Presales Executive...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?