PULSE NAME
When tax season becomes cyberattack season: Phishing and malware campaigns using tax-related lures
WHITE AlienVault 2026-03-19 Modified: 2026-03-20
9
IOCs
LOW VOLUME
During tax season, threat actors exploit the urgency of time-sensitive tax-related emails to trick targets into opening malicious attachments, scanning QR codes, or following link chains. Recent campaigns identified by Microsoft Threat Intelligence use lures around W-2 forms, tax forms, and impersonation of government tax agencies and financial institutions. These campaigns aim to harvest credentials or deliver malware, often using phishing-as-a-service platforms for convincing credential theft and MFA bypass. Notable tactics include using legitimate remote monitoring tools, targeting specific industries and roles like accountants, and employing sophisticated social engineering techniques. The campaigns leverage various file formats, legitimate infrastructure, and multiple user interactions to complicate detection.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
ScreenConnect SimpleHelp Datto
Indicators of Compromise (9)
All FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 45b6b4db1be6698c29ffde9daeb8ffaa344b687d3badded2f8c68c922cdce6e0 2026-03-19
FileHash-SHA256 d422f6f5310af1e72f6113a2a592916f58e3871c58d0e46f058d4b669a3a0fd8 2026-03-19
domain edud.site 2026-03-19
domain gov-irs216.net 2026-03-19
domain irs-doc.com 2026-03-19
domain private-adobe-client.im 2026-03-19
domain smartvault.im 2026-03-19
domain tax-statments2025.com 2026-03-19
domain taxationstatments2025.com 2026-03-19