New Zeusbot bait - IRS phishing

Share with your network!
The controllers of the Zeus botnet have been rotating through several old baits, looking for things that will get unsuspecting users to download attachments and infect themselves. In recent days, they've been trawling fraudulent VISA transactions and "some jerk has posted your picture" in front of us. Today, we're seeing something new. Emails with the subject "You are in a higher tax bracket", from "Tax Commisar", have been making the rounds for the last 20 hours or so. After reminding you that the US uses a progressive income tax, you're told that you're making more money than last year, and that you should review your annual tax report. The included link takes you to a double threat - the page itself tells you that you need a new Flash player, and it will attempt to automatically download (and run) a PDF file. The "Flash updater" is an installer for the Zeus bot, and the PDF file takes advantages of some known vulnerabilities in unpatched Adobe Acrobat versions to take control of your machine if the Flash updater doesn't get it first. Make sure you've grabbed the last Acrobat updates from Adobe, along with all of the other security patches that you should be keeping on top of. Malefactors have been using Acrobat as an abuse vector for a while, and it's just getting worse.