Sep16
5:59 am (UTC-7)   |   by Bernadette Irinco (Technical Communications)

Trend Micro warns users of the latest spam campaign that targets US taxpayers with Foreign Bank and Financial accounts. The said spam rides on the September 23 extended deadline set by the Internal Revenue Service (IRS) for filing ‘FBAR’ or the Report of Foreign Bank and Financial Accounts.

The spammed message bears the subject “Notice of Underreported Income” and lures users to click the link that supposedly contains the tax statement. Users who click the URL are led to a site where they get infected by various ZBOT variants. ZBOT variants are notorious for their information theft routines.Trend Micro detected these ZBOT variants as TSPY_ZBOT.BZJ, TSPY_ZBOT.BZT, TSPY_ZBOT.BZS, and TSPY_ZBOT.COB.

Click for larger view

Figure 1. Bogus IRS Spam

Ever since this spam run began, ZBOT creators have been generating new binaries, probably to avoid detection and removal.

Spammers often ride on the tax season to trick users into giving their credentials and even infecting their PCs with malware. We blogged about it in the following posts:

Trend Micro already detects and blocks this spam attack with its Trend Micro Smart Protection Network. Users are advised to get only their tax statement straight from IRS.

If you're new here, you may want to subscribe to our RSS feed. Thanks for visiting!




9 Responses to “Social Engineering Watch: Another IRS Scam”

Trackbacks

  1. Social Engineering Watch: Another IRS Scam « Friendly Computers Virus Alerts
  2. TrendMicro (TrendMicro)
  3. rukku (RK )
  4. alexandrosilva (Alexos)
  5. MonserrateM (Mitchell Monserrate)
  6. Menardconnect (Menard Osena)
  7. singlesource_it (SingleSource IT)
  8. mponteres (Mark Ponteres)
  9. IRS Spam drains millions daily from victims « FROM THE IGLOO

Leave a Reply



© Copyright 2009 Trend Micro Inc. All rights reserved. Legal Notice