ZeuS circulates in ATO spam

By

Tax Office warns of Trojan virus.

Cybercriminals are circulating a variant of the ZeuS Trojan via a spam campaign that claims to offer tax refunds, the Australian Taxation Office (ATO) has warned.

ZeuS circulates in ATO spam

The scam emails claimed to be from the ATO and contained Trojan.Zbot malware within a zip file named ‘Restore your account’.

Also included in the zip file was a message that asked recipients to provide their personal and credit or debit card details in order to receive a refund.

Tax Commissioner Michael D’Ascenzo warned the community that the ATO would never request those details by email.

“Any email requesting personal and credit or debit card details before a refund can be released is a hoax,” he stated.

According to security vendor Symantec, Trojan.Zbot affected Windows Vista and previous Windows operating systems and was used to steal confidential information from a compromised computer.

It typically gathered system information, online credentials and banking details contained within the Windows Protected Storage (PStore) system.

ZeuS malware was created using Trojan-building toolkits that ranged in price from US$40 ($39) to US$4,000, and could force compromised computers to become part of a botnet.

The malware was believed to have been used in the theft of US$415,000 from the Bullitt County treasury in Kentucky in mid-2009.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Phishing attack nets enormous npm supply chain compromise

Phishing attack nets enormous npm supply chain compromise

Service NSW centralises security, networking in mammoth CloudOps overhaul

Service NSW centralises security, networking in mammoth CloudOps overhaul

VicRoads to phase out passwords in favour of passkeys

VicRoads to phase out passwords in favour of passkeys

Salesloft hacked via GitHub and AWS in March, Mandiant finds

Salesloft hacked via GitHub and AWS in March, Mandiant finds

Log In

  |  Forgot your password?