Go to listing page

Alert! Cybercriminals Leverage Tax-Related Themes to Drop Malware

Alert! Cybercriminals Leverage Tax-Related Themes to Drop Malware
It’s tax season and cybercriminals have already begun spamming users with different tax-related scams. The IRS has highlighted the rising popularity of such scams as it reported a staggering loss of $5.7 billion last year, over twice the amount reported in 2021. 

The latest attack campaign

Researchers are warning about a hacker group, tracked as TACTICAL#OCTOPUS, using tax-related email lures to spread malware.
  • The group uses valid employee W-2 tax documents, I-9 forms, and real estate purchase contracts to trick users into downloading malware onto their systems.
  • The attack typically starts with emails that contain password-protected files with tax-related names like TitleContractDocs.zip or JRCLIENTCOPY3122.zip.
  • Within the zip file is a single image file that further causes the execution of malware in secondary stages. 
  • The malware enables hackers to gain access to victims’ systems and capture clipboard data and track keystrokes.

Why is tax season popular among cyber actors?

  • The time-sensitive nature of tax season appeals to threat actors as they can leverage the tax filing deadline to put pressure on individuals, which increases the likelihood of falling victim to these scams.
  • Moreover, the large amount of personal and financial information that is filed during the tax returns is valuable for attackers as it can be used for identity theft, tax fraud, or other fraudulent activities.

Emotet also makes its way into the tax scam

  • Last week, the operators behind the notorious Emotet trojan were also found using tax-related lures against taxpayers. 
  • In the campaign, the attackers impersonated an inspector from the IRS and sent malicious emails titled IRS Tax Forms W-9.

How to stay safe?

The IRS has issued a guideline to alert taxpayers of emerging scams in the new tax filing season. It has urged individuals to remain vigilant against email and text scams that are related to tax refunds. Additionally, the agency has started a Dirty Dozen list of common scams that taxpayers may encounter at any time during filing season.
Cyware Publisher

Publisher

Cyware