Xero users targeted by info stealer malware

By
Follow google news

Sophisticated phishing attack.

Customers of web-based accounting software provider Xero were hit by a phishing attack that attempts to plant malware on their computers last month, researchers have revealed.

Xero users targeted by info stealer malware

Security vendor Trustwave said it discovered what it called a sophisticated phishing email campaign in August that purported to be from Xero.

The messages were similar to Xero monthly billing notifications, and asked users to review their invoices by clicking on a link in the email.

If the targeted users clicked on the link, a ZIP archive containing obfuscated Javascript was downloaded to their computers, Trustwave's analysis showed.

The payload is a variant of the Dridex inforrmation stealing malware that was used as recently as April to attack Australian bank customers.

Dridex is able to intercept information that users enter into web browsers such as Internet Explorer, Google Chrome, and Mozilla Firefox, and send it to control and command servers with transport layer security (TLS) encryption.

Xero has more than half a milllion customers in Australia.

Trustwave noted that the Xero campaign might be part of a larger operation targeting accounting software customers.

The security vendor said it had found a similar attack against MYOB in late August, which attempted to download the Ursnif Trojan. 

Accounting software provider Quickbooks also appears to be a target, along with cloud storage provider Dropbox, Trustwave said.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Australia Post is co-developing two ML models to prioritise its incident queue

Australia Post is co-developing two ML models to prioritise its incident queue

Medibank reveals attack vector and cost of 2022 security breach

Medibank reveals attack vector and cost of 2022 security breach

Another serious Linux local privesc bug surfaces

Another serious Linux local privesc bug surfaces

Log In

  |  Forgot your password?