New Verizon Wireless-themed Zeus campaign hits

Share this article:
A malicious spam campaign masquerading this weekend as a message from Verizon Wireless was propagating the Zeus trojan, according to researchers at internet security vendor SonicWALL.

The messages, which seemed to be coming from Verizon Wireless Customer Service, falsely informed recipients that their credit balance was over the limit and asked them to check their account details by using a tool attached to the message.

The message was not really from Verizon Wireless and the attachment contained the notorious data-stealing trojan Zeus, also known as Zbot, researchers at SonicWALL said.

Deepen Desai, senior software engineer at SonicWALL, told SCMagazineUS.com on Monday that the malicious messages started being sent on Friday morning at a rate of about 200,000 emails per hour, which continued throughout the weekend. By this morning, the campaign stopped, but not before attackers sent the message approximately nine million times, he said.

“This [campaign] was short, but the volume was very high compared to what we have seen in the past,” Desai said.

Over the weekend, those behind the scam "repackaged" the trojan six different times to avoid anti-virus detection, Desai said.

Zeus has been circulating since at least 2006. The trojan typically aims to capture infected users' banking login credentials and send them back to a command-and-control hub.

A Verizon spokeswoman said the company was aware of the spam run.

“We're aware of this spam/phishing message being sent to our customers over the past several days, and have taken steps to stop it from occurring,” she told SCMagazineUS.com in an email Monday. “As with other unknown emails or links, we'd encourage people who receive this message not to click on it, and delete it immediately.”

Recently, Zeus has been propagated through spam messages claiming to be a password reset request from MySpace, a notice from the IRS and a critical update for Microsoft Outlook.
Share this article:

Sign up to our newsletters

More in News

AOL Mail hack furthers spam campaign using spoofed accounts

AOL confirmed on Monday that it was aware of the issue and working to remediate the situation.

Backdoors in Wi-Fi routers, said to be closed, can be reopened

Backdoors in Wi-Fi routers, said to be closed, ...

Although said to be patched, researcher Eloi Vanderbeken discovered during the Easter holiday that backdoors existing in certain wireless routers can be reactivated.

Apple ships Mac OS X updates, fixes several code execution bugs

Apple ships Mac OS X updates, fixes several ...

Among the addressed vulnerabilities, was a bug affecting WindowServer, which could allow an attacker to execute malicious code outside the sandbox.