All the latest UK technology news, reviews and analysis

Zeus attacks targeting financial investment market

by Shaun Nichols

27 Apr 2011

Be the first to comment

  • Tweet this

New variants of the Zeus malware package are being used in an attack targeting financial investors.

Security vendor Trusteer said in a recent report that samples of the malware have been spotted in connection with URS Investment Fund, a phoney investment site which seeks to trick users into uploading money transfers to an account controlled by the attacker.

The attack uses the ability of Zeus to locally alter HTML files on infected machines, allowing attack code to be presented on otherwise safe web pages.

In this case, the malware has been injecting pages with bogus banner ads attempting to lure people to the URS Investment Fund site.

Popular news and financial sites such as Forbes, AOL, Citibank and Amazon have all been targeted.

"This new attack is noteworthy for the level of sophistication and depth and breadth of content that the criminals have developed to make the scam appear legitimate and believable," said Trusteer chief technology officer and head of research Amit Klein.

"Unlike many Zeus attacks, this is less about the attack code and all about selling the fraud scheme."

The incident is the latest in a long-running legacy of financial attacks and scams connected to the Zeus malware family. Known for its ease of use, Zeus has become popular with cyber criminals for phishing and financial fraud operations.

Paula Musich, a senior analyst for enterprise networking and security at Current Analysis, said that Zeus and other recent malware outbreaks are causing some enterprises to scramble for new security protection.

Musich told V3.co.uk that, rather than invest time in properly educating staff to avoid phishing and social engineering attacks, companies are looking for software solutions to protect against attacks.

"I don't think it has changed enterprise mentality, as much as sent them looking for another technology," she said. "The mindset is to see if they can't find some 'silver bullet' technology."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

38%

0%

10%

52%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Java Developer, Algo Trading, FX, Trading Strategies

Java Deveoper/Programmer/Software Engineer, Algo Trading...

Lead and Senior Developers Wanted

Austin Fraser has the pleasure of appointing a number...

Java Developer - Great move up for a Junior Developer

Austin Fraser has the pleasure of appointing a Java Developer...

Senior J2EE Application Developer

Austin Fraser has the pleasure of appointing a Senior...

To send to more than one email address, simply separate each address with a comma.