US-CERT: US Tax Season Phishing Scams and Malware Campaigns
March 26, 2010 -- In the past, US-CERT has received reports of an increased number of phishing scams and malware campaigns that take advantage of the United States tax season. Due to the upcoming tax deadline, US-CERT reminds users to remain cautious when receiving unsolicited email that could be part of a potential phishing scam or malware campaign.
These phishing scams and malware campaigns may include the following: information that refers to a tax refund, warnings about unreported or under-reported income, offers to assist in filing for a refund, or details about fake e-file websites.
These messages, which appear to be from the IRS, may ask users to submit personal information via email or may instruct the user to follow a link to a website that requests personal information or contains malicious code.
At this time, US-CERT is aware of public reports indicating that there is active circulation of a tax season malware campaign. This malware campaign may be using malicious code commonly known as Zeus or Zbot.
US-CERT encourages users and administrators to take the following measures to protect themselves from these types of phishing scams and malware campaigns:
* Do not follow unsolicited web links in email messages.
* Maintain up-to-date antivirus software.
* Refer to the IRS website related to phishing, email, and bogus website scams for scam samples and reporting information.
* Refer to the Recognizing and Avoiding Email Scams (pdf) document for more information on avoiding email scams.
* Refer to the Avoiding Social Engineering and Phishing Attacks document for more information on social engineering attacks.
Source: US-CERT
Related articles
- US-CERT: US Tax Season Phishing Scams and Malware Campaigns
- Report: Malware and Spam Up 70% on Social Networks
- eCrime Web site Longevity Drops
- McAfee Identifies the Most Dangerous and Safest Web Search Keywords
- VeriSign Internet Trust Index Released
- Online Consumer Privacy Protection
- Deloitte: Cyber Crime "Clear and Present Danger"
- Symantec Solutions Passes Industry Security Tests
- Comcast partners with Symantec on Norton Security Suite Offering
- Webroot Expands Globally
- Symantec to Acquire Gideon Technologies
- the Rubicon Project Launches Rubicon Security

