Who did not see thing one comming? Verified by…

Visa and others.  The first time the page came up “verified by Visa” you said “cool this is a very good thing Visa is making the web safer”.  If you thought that you can now go to the back of the class.  You should have been thinking what sort of phishing scam is this?  Where is the URL bar for this popup and why would I sign up for this service from this little dialog on some site?  Does Visa even have a website?  Does my bank know about this?

Now for those of you at the back of the class, the zbot botnet has been augmented to shoot phish in a barrel.  You are the phish, unfortunately.  Thank you, Visa for the swimming lessons (NOT).

Click to read more news on the zbot botnet and how it is mimicking the Verified by screens.

http://www.sans.org/newsletters/newsbites/newsbites.php?vol=12&issue=56#sID301