Xero users targeted by info stealer malware

By

Sophisticated phishing attack.

Customers of web-based accounting software provider Xero were hit by a phishing attack that attempts to plant malware on their computers last month, researchers have revealed.

Xero users targeted by info stealer malware

Security vendor Trustwave said it discovered what it called a sophisticated phishing email campaign in August that purported to be from Xero.

The messages were similar to Xero monthly billing notifications, and asked users to review their invoices by clicking on a link in the email.

If the targeted users clicked on the link, a ZIP archive containing obfuscated Javascript was downloaded to their computers, Trustwave's analysis showed.

The payload is a variant of the Dridex inforrmation stealing malware that was used as recently as April to attack Australian bank customers.

Dridex is able to intercept information that users enter into web browsers such as Internet Explorer, Google Chrome, and Mozilla Firefox, and send it to control and command servers with transport layer security (TLS) encryption.

Xero has more than half a milllion customers in Australia.

Trustwave noted that the Xero campaign might be part of a larger operation targeting accounting software customers.

The security vendor said it had found a similar attack against MYOB in late August, which attempted to download the Ursnif Trojan. 

Accounting software provider Quickbooks also appears to be a target, along with cloud storage provider Dropbox, Trustwave said.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

NSW Police to embark on $126m IT overhaul

NSW Police to embark on $126m IT overhaul

CBA looks to GenAI to assist 1200 'security champions'

CBA looks to GenAI to assist 1200 'security champions'

Australia's super funds told to assess authentication controls

Australia's super funds told to assess authentication controls

WestJet probes cyber security incident

WestJet probes cyber security incident

Log In

  |  Forgot your password?