Intuit payroll free trial email launches malware attack

Filed Under: Malware, Spam

Intuit and malwareHave you received an unsolicited email from - what appears to be - Intuit Supplies Group? Be on your guard..

Malware is being spammed out to internet email users, posing as a message from the payroll software company Intuit.

The emails have the subject line "Your Intuit Online Payroll Free Trial", but attached to the messages is a ZIP file containing a malicious Trojan horse.

Malicious email claiming to come from Intuit. Click for larger version

The email looks convincing enough, and you can understand how some individuals and small businesses might feel tempted to learn more about the offer which they believe has been sent to them.

However, the attached ZIP file (which is 196,096 bytes in size) contains a malicious file called

Intuit Online Payroll Free Trial Detailed information.exe

which is designed to compromise the recipient's computer.

Of course, the emails are not really from Intuit - they are innocent casualties of the attack (their brand is being tarnished). Similarly, internet users who open the file attached to the malicious spam are at risk of falling victim to a malware infection.

Sophos is intercepting the messages as spam, and is adding detection of the Trojan horse file to its security products as Troj/Agent-TZG.

, ,

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title="" rel=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <pre> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

About the author

Graham Cluley is senior technology consultant at Sophos. The readers of Computer Weekly voted him security blogger of the year in 2009 and 2010, and he pipped Stephen Fry to the title of "Twitter user of the year" too. Which was nice. He was also named "Best Security Blogger" by the readers of SC Magazine in 2011. You can subscribe to Graham's updates on Facebook, follow him on Twitter and circle him on Google Plus for regular updates.