Cloud-based payroll providers warned of new malware risk
Online payroll providers are being told to tighten up their login procedures, following the discovery of a new malware threat by Trusteer.
The security vendor has uncovered a Zeus that targets cloud-based payroll providers, and fears it could be used by cybercriminals to steal large sums of money from companies that use online services.
Trusteer researchers have pinpointed a version of this malware that targets users of Canada-based payroll provider Ceridian, allowing hackers to infiltrate the service. Zeus captures a screenshot of the Ceridian login page when a user infected with the Trojan visits the site. This image records the employee’s username, password, company number and the icon needed to bypass the firm’s image-based authentication system.