← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Security brief: tax scams aim to steal funds from taxpayers
Threat actors are exploiting tax season with numerous campaigns leveraging tax themes to deliver malware, remote monitoring tools, fraud attempts, and credential phishing. Over a hundred campaigns have been observed in 2026, with a notable increase in remote monitoring and management (RMM) payloads. Tactics include impersonating tax agencies, claiming expired documents, and requesting tax filing support. While primarily targeting the United States, campaigns have also been observed in Canada, Australia, Switzerland, and Japan. Notable actors include TA4922, a newly designated threat group delivering malware from the Winos4.0 ecosystem, and TA2730, focusing on credential phishing for financial institutions. Business email compromise actors are also using tax form lures to steal financial and personal data. These campaigns demonstrate the ongoing exploitation of timely and topical themes by cybercriminals to deceive users.
MITRE ATT&CK & Malware Families
Indicators of Compromise (19)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| IPv4 | 121.127.232.253 | — | 2026-03-30 | |
| FileHash-MD5 | 04e20b06dad0a6b69527a6efea668a31 | — | 2026-03-30 | |
| FileHash-MD5 | ab11a32f0d617e50eb0c710d63128f79 | — | 2026-03-30 | |
| FileHash-SHA1 | 5fa97aaf219b223159f9487b296bb916f073e4a0 | — | 2026-03-30 | |
| FileHash-SHA1 | 7ba88ef7b2dce865d2bc4e95e982bf68dfff1ea4 | — | 2026-03-30 | |
| FileHash-SHA256 | 844202972ff19afa760447fc87963de0fbbc0ebc69d50164f03ecf5d4e67952f | — | 2026-03-30 | |
| FileHash-SHA256 | d338a7f85737cac1a7b4b5a1cca94e33d0aa8260548667c6733225d4c20cb848 | — | 2026-03-30 | |
| URL | https://www.upsystems.one/Alex.exe | — | 2026-03-30 | |
| domain | akcjdrya.com | — | 2026-03-30 | |
| domain | bksgcefzqyb.com | — | 2026-03-30 | |
| domain | buwxkiy.com | — | 2026-03-30 | |
| domain | eodrggi.com | — | 2026-03-30 | |
| domain | gyglowcq.com | — | 2026-03-30 | |
| domain | iuzndfqr.com | — | 2026-03-30 | |
| domain | nirbsff.com | — | 2026-03-30 | |
| domain | rmwztbrr.com | — | 2026-03-30 | |
| domain | whghfpytehu.com | — | 2026-03-30 | |
| domain | wijgzsfh.com | — | 2026-03-30 | |
| hostname | www.upsystems.one | — | 2026-03-30 |