← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
When tax season becomes cyberattack season: Phishing and malware campaigns using tax-related lures
During tax season, threat actors exploit the urgency of time-sensitive tax-related emails to trick targets into opening malicious attachments, scanning QR codes, or following link chains. Recent campaigns identified by Microsoft Threat Intelligence use lures around W-2 forms, tax forms, and impersonation of government tax agencies and financial institutions. These campaigns aim to harvest credentials or deliver malware, often using phishing-as-a-service platforms for convincing credential theft and MFA bypass. Notable tactics include using legitimate remote monitoring tools, targeting specific industries and roles like accountants, and employing sophisticated social engineering techniques. The campaigns leverage various file formats, legitimate infrastructure, and multiple user interactions to complicate detection.
MITRE ATT&CK & Malware Families
Indicators of Compromise (9)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 45b6b4db1be6698c29ffde9daeb8ffaa344b687d3badded2f8c68c922cdce6e0 | — | 2026-03-19 | |
| FileHash-SHA256 | d422f6f5310af1e72f6113a2a592916f58e3871c58d0e46f058d4b669a3a0fd8 | — | 2026-03-19 | |
| domain | edud.site | — | 2026-03-19 | |
| domain | gov-irs216.net | — | 2026-03-19 | |
| domain | irs-doc.com | — | 2026-03-19 | |
| domain | private-adobe-client.im | — | 2026-03-19 | |
| domain | smartvault.im | — | 2026-03-19 | |
| domain | tax-statments2025.com | — | 2026-03-19 | |
| domain | taxationstatments2025.com | — | 2026-03-19 |