<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Spamvertised Verizon-themed &#8216;Your Bill Is Now Available&#8217; emails lead to ZeuS crimeware</title>
	<atom:link href="http://blog.webroot.com/2012/03/29/spamvertised-verizon-themed-your-bill-is-now-available-emails-lead-to-zeus-crimeware/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.webroot.com/2012/03/29/spamvertised-verizon-themed-your-bill-is-now-available-emails-lead-to-zeus-crimeware/</link>
	<description>WEBROOT - INSIGHTS INTO THREATS AND TRENDS FROM OUR INTERNET SECURITY EXPERTS</description>
	<lastBuildDate>Thu, 23 May 2013 07:00:37 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Fake &#8216;Verizon Wireless Statement&#8221; themed emails lead to Black Hole Exploit Kit &#124; Webroot Threat Blog - Internet Security Threat Updates from Around the World</title>
		<link>http://blog.webroot.com/2012/03/29/spamvertised-verizon-themed-your-bill-is-now-available-emails-lead-to-zeus-crimeware/#comment-115940</link>
		<dc:creator><![CDATA[Fake &#8216;Verizon Wireless Statement&#8221; themed emails lead to Black Hole Exploit Kit &#124; Webroot Threat Blog - Internet Security Threat Updates from Around the World]]></dc:creator>
		<pubDate>Thu, 21 Feb 2013 13:34:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=6449#comment-115940</guid>
		<description><![CDATA[[...] customers across the globe in an attempt to trick them into interacting with the fake emails. Throughout 2012, we intercepted two campaigns pretending to come from the company, followed by another campaign [...]]]></description>
		<content:encoded><![CDATA[<p>[...] customers across the globe in an attempt to trick them into interacting with the fake emails. Throughout 2012, we intercepted two campaigns pretending to come from the company, followed by another campaign [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spamvertised &#8216;Your Recent eBill from Verizon Wireless&#8217; themed emails serve client-side exploits and malware &#171; Webroot Threat Blog &#8211; Internet Security Threat Updates from Around the World</title>
		<link>http://blog.webroot.com/2012/03/29/spamvertised-verizon-themed-your-bill-is-now-available-emails-lead-to-zeus-crimeware/#comment-101384</link>
		<dc:creator><![CDATA[Spamvertised &#8216;Your Recent eBill from Verizon Wireless&#8217; themed emails serve client-side exploits and malware &#171; Webroot Threat Blog &#8211; Internet Security Threat Updates from Around the World]]></dc:creator>
		<pubDate>Fri, 04 Jan 2013 13:10:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=6449#comment-101384</guid>
		<description><![CDATA[[...] 2012, we intercepted two malicious campaigns impersonating Verizon Wireless in an attempt to trick its customers into clicking on links pointing [...]]]></description>
		<content:encoded><![CDATA[<p>[...] 2012, we intercepted two malicious campaigns impersonating Verizon Wireless in an attempt to trick its customers into clicking on links pointing [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cybercriminals impersonate Verizon Wireless, serve client-side exploits and malware &#171; Webroot Threat Blog &#8211; Internet Security Threat Updates from Around the World</title>
		<link>http://blog.webroot.com/2012/03/29/spamvertised-verizon-themed-your-bill-is-now-available-emails-lead-to-zeus-crimeware/#comment-79122</link>
		<dc:creator><![CDATA[Cybercriminals impersonate Verizon Wireless, serve client-side exploits and malware &#171; Webroot Threat Blog &#8211; Internet Security Threat Updates from Around the World]]></dc:creator>
		<pubDate>Sat, 27 Oct 2012 07:01:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=6449#comment-79122</guid>
		<description><![CDATA[[...] last time we intercepted a Verizon Wireless themed malicious campaign was in March 2012. We expect to see more campaigns impersonating this company, thanks to the [...]]]></description>
		<content:encoded><![CDATA[<p>[...] last time we intercepted a Verizon Wireless themed malicious campaign was in March 2012. We expect to see more campaigns impersonating this company, thanks to the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spamvertised &#8216;US Airways reservation confirmation&#8217; themed emails serve exploits and malware &#171; Webroot Threat Blog</title>
		<link>http://blog.webroot.com/2012/03/29/spamvertised-verizon-themed-your-bill-is-now-available-emails-lead-to-zeus-crimeware/#comment-72653</link>
		<dc:creator><![CDATA[Spamvertised &#8216;US Airways reservation confirmation&#8217; themed emails serve exploits and malware &#171; Webroot Threat Blog]]></dc:creator>
		<pubDate>Tue, 18 Sep 2012 07:00:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=6449#comment-72653</guid>
		<description><![CDATA[[...] then, we found an identical campaign structure between the US Airways themed campaign and the “Spamvertised Verizon-themed ‘Your Bill Is Now Available’ emails lead to ZeuS crimeware” ; “Spamvertised LinkedIn notifications serving client-side exploits and malware“ campaigns, [...]]]></description>
		<content:encoded><![CDATA[<p>[...] then, we found an identical campaign structure between the US Airways themed campaign and the “Spamvertised Verizon-themed ‘Your Bill Is Now Available’ emails lead to ZeuS crimeware” ; “Spamvertised LinkedIn notifications serving client-side exploits and malware“ campaigns, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ddanchev</title>
		<link>http://blog.webroot.com/2012/03/29/spamvertised-verizon-themed-your-bill-is-now-available-emails-lead-to-zeus-crimeware/#comment-61837</link>
		<dc:creator><![CDATA[ddanchev]]></dc:creator>
		<pubDate>Wed, 18 Jul 2012 13:15:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=6449#comment-61837</guid>
		<description><![CDATA[Hi Betty,

Basically, once the client-side exploitation take place, a copy of the Pony malware will be dropped on the infected hosts. It will actively look for accounting data on the infected PC and send it back to the cybercriminals. It will then downloading its secondary payload, which in this case is the ZeuS crimeware aiming to steal online banking credentials and hijack online banking sessions.

Even if Webroot SecureAnywhere somehow missed any of the malicious files participating in the campaign, its behavior-blocking technology would pick up the malicious attempts to execute, and block them.

Thanks,
Dancho]]></description>
		<content:encoded><![CDATA[<p>Hi Betty,</p>
<p>Basically, once the client-side exploitation take place, a copy of the Pony malware will be dropped on the infected hosts. It will actively look for accounting data on the infected PC and send it back to the cybercriminals. It will then downloading its secondary payload, which in this case is the ZeuS crimeware aiming to steal online banking credentials and hijack online banking sessions.</p>
<p>Even if Webroot SecureAnywhere somehow missed any of the malicious files participating in the campaign, its behavior-blocking technology would pick up the malicious attempts to execute, and block them.</p>
<p>Thanks,<br />
Dancho</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Betty Bealler</title>
		<link>http://blog.webroot.com/2012/03/29/spamvertised-verizon-themed-your-bill-is-now-available-emails-lead-to-zeus-crimeware/#comment-61742</link>
		<dc:creator><![CDATA[Betty Bealler]]></dc:creator>
		<pubDate>Wed, 18 Jul 2012 02:36:40 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=6449#comment-61742</guid>
		<description><![CDATA[Sorry need to speak in laymans&#039; terms.  What would the Verizon themed &#039;your bill is now available&#039; actually do to my pc?  And since I have webroot would I be protected from this?  As I had something infect my contact list twice in the past two months and send out bogus/spam emails to all of my contacts with links.  I&#039;m guessing something may have slipped past the security?]]></description>
		<content:encoded><![CDATA[<p>Sorry need to speak in laymans&#8217; terms.  What would the Verizon themed &#8216;your bill is now available&#8217; actually do to my pc?  And since I have webroot would I be protected from this?  As I had something infect my contact list twice in the past two months and send out bogus/spam emails to all of my contacts with links.  I&#8217;m guessing something may have slipped past the security?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spamvertised &#8216;Your Amazon.com order confirmation&#8217; emails serving client-side exploits and malware &#171; Webroot Threat Blog</title>
		<link>http://blog.webroot.com/2012/03/29/spamvertised-verizon-themed-your-bill-is-now-available-emails-lead-to-zeus-crimeware/#comment-54674</link>
		<dc:creator><![CDATA[Spamvertised &#8216;Your Amazon.com order confirmation&#8217; emails serving client-side exploits and malware &#171; Webroot Threat Blog]]></dc:creator>
		<pubDate>Wed, 13 Jun 2012 15:09:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=6449#comment-54674</guid>
		<description><![CDATA[[...] Spamvertised Verizon-themed ‘Your Bill Is Now Available’ emails lead to ZeuS crimeware [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Spamvertised Verizon-themed ‘Your Bill Is Now Available’ emails lead to ZeuS crimeware [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: A peek inside a managed spam service &#171; Webroot Threat Blog</title>
		<link>http://blog.webroot.com/2012/03/29/spamvertised-verizon-themed-your-bill-is-now-available-emails-lead-to-zeus-crimeware/#comment-49747</link>
		<dc:creator><![CDATA[A peek inside a managed spam service &#171; Webroot Threat Blog]]></dc:creator>
		<pubDate>Thu, 17 May 2012 17:20:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=6449#comment-49747</guid>
		<description><![CDATA[[...] How does the service differentiate itself from the rest of the propositions within the cybercrime ecosystem? By emphasizing on key core competencies such as managed QA (quality assurance) ensuring that the message about the get spammed will successfully bypass anti-spam  filters. Next to this option, the service also offers the availability of graphic designers capable of producing custom layouts on request. Not surprisingly, thanks to the fact that the service is build around the concept of anonymity, a customer could easily request the design of spam templates impersonating Google, Facebook, USPS, LinkedIn, U.S Airways, or Verizon Wireless. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] How does the service differentiate itself from the rest of the propositions within the cybercrime ecosystem? By emphasizing on key core competencies such as managed QA (quality assurance) ensuring that the message about the get spammed will successfully bypass anti-spam  filters. Next to this option, the service also offers the availability of graphic designers capable of producing custom layouts on request. Not surprisingly, thanks to the fact that the service is build around the concept of anonymity, a customer could easily request the design of spam templates impersonating Google, Facebook, USPS, LinkedIn, U.S Airways, or Verizon Wireless. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spamvertised &#8216;US Airways&#8217; themed emails serving client-side exploits and malware &#171; Webroot Threat Blog</title>
		<link>http://blog.webroot.com/2012/03/29/spamvertised-verizon-themed-your-bill-is-now-available-emails-lead-to-zeus-crimeware/#comment-44154</link>
		<dc:creator><![CDATA[Spamvertised &#8216;US Airways&#8217; themed emails serving client-side exploits and malware &#171; Webroot Threat Blog]]></dc:creator>
		<pubDate>Tue, 03 Apr 2012 19:08:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=6449#comment-44154</guid>
		<description><![CDATA[[...] launched by the same gang of cybercriminals that recently launched the following campaigns &#8220;Spamvertised Verizon-themed ‘Your Bill Is Now Available’ emails lead to ZeuS crimeware&#8221; ; &#8220;Spamvertised LinkedIn notifications serving client-side exploits and [...]]]></description>
		<content:encoded><![CDATA[<p>[...] launched by the same gang of cybercriminals that recently launched the following campaigns &#8220;Spamvertised Verizon-themed ‘Your Bill Is Now Available’ emails lead to ZeuS crimeware&#8221; ; &#8220;Spamvertised LinkedIn notifications serving client-side exploits and [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
