PULSE NAME
Security brief: tax scams aim to steal funds from taxpayers
WHITE AlienVault 2026-03-30 Modified: 2026-03-30
19
IOCs
MEDIUM VOLUME
Threat actors are exploiting tax season with numerous campaigns leveraging tax themes to deliver malware, remote monitoring tools, fraud attempts, and credential phishing. Over a hundred campaigns have been observed in 2026, with a notable increase in remote monitoring and management (RMM) payloads. Tactics include impersonating tax agencies, claiming expired documents, and requesting tax filing support. While primarily targeting the United States, campaigns have also been observed in Canada, Australia, Switzerland, and Japan. Notable actors include TA4922, a newly designated threat group delivering malware from the Winos4.0 ecosystem, and TA2730, focusing on credential phishing for financial institutions. Business email compromise actors are also using tax form lures to steal financial and personal data. These campaigns demonstrate the ongoing exploitation of timely and topical themes by cybercriminals to deceive users.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Winos4.0 ValleyRAT
Indicators of Compromise (19)
All IPv4 FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
IPv4 121.127.232.253 2026-03-30
FileHash-MD5 04e20b06dad0a6b69527a6efea668a31 2026-03-30
FileHash-MD5 ab11a32f0d617e50eb0c710d63128f79 2026-03-30
FileHash-SHA1 5fa97aaf219b223159f9487b296bb916f073e4a0 2026-03-30
FileHash-SHA1 7ba88ef7b2dce865d2bc4e95e982bf68dfff1ea4 2026-03-30
FileHash-SHA256 844202972ff19afa760447fc87963de0fbbc0ebc69d50164f03ecf5d4e67952f 2026-03-30
FileHash-SHA256 d338a7f85737cac1a7b4b5a1cca94e33d0aa8260548667c6733225d4c20cb848 2026-03-30
URL https://www.upsystems.one/Alex.exe 2026-03-30
domain akcjdrya.com 2026-03-30
domain bksgcefzqyb.com 2026-03-30
domain buwxkiy.com 2026-03-30
domain eodrggi.com 2026-03-30
domain gyglowcq.com 2026-03-30
domain iuzndfqr.com 2026-03-30
domain nirbsff.com 2026-03-30
domain rmwztbrr.com 2026-03-30
domain whghfpytehu.com 2026-03-30
domain wijgzsfh.com 2026-03-30
hostname www.upsystems.one 2026-03-30