Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

October 18th, 2010, 06:15 GMT · By

Number of Fake Electronic Tax Payment Emails Has Spiked

SHARE:

Adjust text size:


ZeuS distribution campaign produces failed tax payment emails
Enlarge picture
Security researchers warn that a ZeuS distribution campaign producing emails about failed electronic tax payments, has significantly increased its aggressiveness over the weekend.

The rogue emails started hitting inboxes earlier last week and come with a subject of "Your Tax Payment ID ######### is failed. Update information" (where # is a single digit).

Their from field is spoofed to appear as if they are originating from "EFTPS Tax Payment" <customers@eftps.gov> and instruct users that their tax payments submitted through the Electronic Federal Tax Payment System has (EFTPS) failed.

Furthermore, the messages claim that the payment failed with an R21 error code and provide a link allegedly to obtain additional information.

Clicking on this link takes recipients through a series of redirects until they land on a drive-by download page, where their computers are targeted with exploits for outdated versions of several popular applications.

Successful exploitation results in a variant of the infamous ZeuS banking trojan being installed on the targeted systems.

This malware is commonly used by fraudsters to steal online banking credentials, credit card details and other sensitive information.

According to researchers from email security provider AppRiver, the number of these ZeuS distribution emails has spiked during Saturday, with over 100 new domains being used in the attack.

"At one point this morning we were seeing rates at nearly thirty thousand per minute of these messages hitting our filters," AppRiver's Troy Gill writes.

The sudden increase might have been triggered by the fact that Friday, October 15, was the deadline for submitting the quarterly tax payments in US and people would have been more vulnerable.

The Electronic Federal Tax Payment System (EFTPS) dates back to 1996 and starting with January next year, it will become the default tax payment method for businesses.

ZeuS is a sophisticated threat that poses a lot of danger to companies and organizations. Last month, authorities in US, UK and Ukraine dismantled a network of criminals, who used the trojan to steal more than $70 millions from businesses.

TELL US WHAT YOU THINK:

1,513 hits · 2 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Rogue LinkedIn Emails Direct Users to Zbot Drive-By Download

New ZBot Distribution Campaigns in Circulation

New Wave of Zbot-Infected Emails

New Flight Ticket Spam Distributes Zbot

Zbot Pushers Claim Eminem Is Dead

READER COMMENTS:


Comment #1 by: les on 19 Oct 2010, 17:09 UTC reply to this comment

how did they obtain my emaill address?


Comment #2 by: Steve on 20 Oct 2010, 13:02 UTC reply to this comment

I've been getting a few dozen of them a day and I have forwarded every one of them to spoof@millersmiles.co.uk

I could tell that they were a scam. But even if I were that gullible, the fact that I am a British citizen and live in the UK kind of blows the whole thing out of the water.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM