A group of attackers is using a combination of Google search-engine optimization (SEO) for banking-related keywords, compromised websites, and malicious Word macros to infect users with the Zeus Panda bank credential stealer. Attackers have used SEO poisoning in the past to spread malware, but this group is using the technique in a particularly crafty manner to ensure malicious links are seen by people who regularly use a specific bank, essentially profiling victims before infection.
Read full news article on ZDNet
