Symantec Connect
  • Login
  • Register
  • Security
    • All of Connect
    • Backup and Archiving
    • Endpoint Management & Virtualization
    • Storage and Clustering
    • Security
    • Inside Symantec
    • Vision User Conference
    • Partners
    • Developers
    •  
  • Overview
  • Forums
  • Articles
  • Blogs
  • Downloads
  • Events
  • Videos
  • Groups
  • Ideas
Login to participate
Security ResponseRSS

Look Who is Taking Advantage of the IRS Deadline

Mayur Kulkarni
September 10th, 2009
Tags: Endpoint Protection (AntiVirus), Security, Spam, Security Response
Facebook Twitter

The IRS settlement offers for U.S. taxpayers holding accounts in foreign banks end on September 23, 2009. Using these offers, one can fully disclose and pay their back taxes, interest, and penalties. In return, the IRS will go back and scrutinize only a limited number of tax years, along with lower penalties and no criminal prosecution. Legitimate FAQs on the settlement offered by the IRS can be found here, with additional information found here.

Spammers are using this deadline to expand their network, using malicious attacks and sending fake IRS email notifications to recipients. These emails do not mention the deadline, but they explicitly describe the issue as “Unreported/Underreported income.” Users might possibly panic over the subject line “Notice of Underreported income,” and download the executable “tax-statement.exe,” detected as Downloader by Symantec antivirus.

Example Image of the email:

look1.jpg

Users are redirected to a malicious IRS look-alike site if they click the URL inside these emails. Here, users are requested to review their tax statement and indirectly coerced to “download and execute” the statement. Needless to say, if users follow these instructions, their machines will be infected.

look2.jpg

The IRS has excellent phishing-related tips that can be found here, to help users from falling victim to these traps. All financial institutions provide similar instructions to help their customers ward off phishing attempts. This is not the first phishing attempt on the IRS; however, Symantec will be actively watching for similar phishing attacks during the following weeks.

Note: Thanks to Paresh Joshi for the contributed content

0 votes
  • Mayur Kulkarni's blog
  • Comments RSS Feed

About Security Response Blog

Our security research centers around the world provide unparalleled analysis of and protection from malware, security risks, vulnerabilities, and spam.
Filter by:

Recent Blog Posts

  • Beyond the Initial Compromise
    Greg Ahmad - March 18, 2010
  • Passwords—Can’t Live With ‘em, Can’t Live Without ‘em
    Kevin Haley - March 17, 2010
  • New Healthcare IT Landscape and Related Security Needs
    Alessandro Tatti - March 17, 2010
  • Fraudsters Running a Classified Ad Campaign
    Mathew Maniyara - March 16, 2010
  • Mass Phishing of Retail Electronic Payment Brands
    Mathew Maniyara - March 15, 2010

Blog Tags

10.x 11.x 9.x and Earlier Antivirus2010 Backdoor.Tidserv Brightmail Gateway Emerging Threats Endpoint Encryption Endpoint Protection (AntiVirus) Endpoint Protection Small Business Enterprise Security Manager Evolution of Security General Symantec IT Healthcare Landscape IT Risk Management Internet Security Threat Report Live PC Care Malicious Code Misleading Applications Mobile & Wireless Online Fraud Password Management Restore Security Security Risks Spam Sykipot SymbOS.Exy Symbian Trojan.FakeAV Trojan.Zbot VirusDoctor Vulnerabilities & Exploits Windows Zeus
© 2010
  • Symantec Corporation
  • Contact Us
  • Get RSS
  • Privacy Policy
  • Symantec.com