ZeuS circulates in ATO spam

 

Tax Office warns of Trojan virus.

Cybercriminals are circulating a variant of the ZeuS Trojan via a spam campaign that claims to offer tax refunds, the Australian Taxation Office (ATO) has warned.

The scam emails claimed to be from the ATO and contained Trojan.Zbot malware within a zip file named ‘Restore your account’.

Also included in the zip file was a message that asked recipients to provide their personal and credit or debit card details in order to receive a refund.

Tax Commissioner Michael D’Ascenzo warned the community that the ATO would never request those details by email.

“Any email requesting personal and credit or debit card details before a refund can be released is a hoax,” he stated.

According to security vendor Symantec, Trojan.Zbot affected Windows Vista and previous Windows operating systems and was used to steal confidential information from a compromised computer.

It typically gathered system information, online credentials and banking details contained within the Windows Protected Storage (PStore) system.

ZeuS malware was created using Trojan-building toolkits that ranged in price from US$40 ($39) to US$4,000, and could force compromised computers to become part of a botnet.

The malware was believed to have been used in the theft of US$415,000 from the Bullitt County treasury in Kentucky in mid-2009.

Copyright © iTnews.com.au . All rights reserved.


ZeuS circulates in ATO spam
"^^ obvious smear campaign is obvious http://louidleahy.sys-con.com/ Vested interest much?"
By jburb
 
Tags
 
 
Comments: 2
Louis Leahy
Feb 28, 2011 1:59 PM
This is even more significantly worrisome given the ATO has championed the adoption of the single sign on concept throughout multiple Government Departments with now over 300,000 participants. If a computer is breached the attackers have access to tamper with multiple databases to conduct fraud. Auskey needs to be dramatically overhauled and a proper authentication interface implemented to protect users. Single sign on systems such as this and the one adopted by Google will put users at increased risk of identity theft because they are being deployed with outdated easily compromised authentication routines.
jburb
Mar 1, 2011 8:11 AM
^^ obvious smear campaign is obvious
http://louidleahy.sys-con.com/

Vested interest much?
Comments have been disabled for this article.
 
 
Top Stories
NRMA builds pre-emptive insurance claims tool
Google Earth integration mulled.
 
Optus buys Perth-based vividwireless
Plans hybrid TD/FD-LTE mobile broadband network.
 
Health rolls out Windows 7 thin clients
To deliver 4500 virtual desktops by May.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Would you be concerned about your business' email data being hosted offshore?

   |   View results
Yes
  85%
 
No
  15%
TOTAL VOTES: 391

Vote