• Login
Whats Current In
No Result
View All Result
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development
No Result
View All Result
Whats Current In
No Result
View All Result
Home Cyber Security

Microsoft: Phishing attack targets accountants as Tax Day approaches

Lawrence Abrams by Lawrence Abrams
April 13, 2023
Reading Time: 3 mins read
0
Beware: Hackers now use OneNote attachments to spread malware

Phishing attack

RELATED POSTS

New Horabot campaign takes over victim’s Gmail, Outlook accounts

Windows 11 will let you view phone photos in File Explorer

Harvard Pilgrim Health Care ransomware attack hits 2.5 million people

Microsoft is warning of a phishing campaign targeting accounting firms and tax preparers with remote access malware allowing initial access to corporate networks.

With the USA reaching the end of its annual tax season, accountants are scrambling to gather clients’ tax documents to complete and file their tax returns.

Due to this, it makes it an ideal time for threat actors to target tax preparers, hoping that they mistakenly open malicious files that they would generally be more careful with when less busy.

This is exactly what Microsoft sees in a new phishing scam targeting tax professionals to install the Remcos remote access trojan malware.

“With U.S. Tax Day approaching, Microsoft has observed phishing attacks targeting accounting and tax return preparation firms to deliver the Remcos remote access trojan (RAT) and compromise target networks beginning in February of this year,” Microsoft warns in a new report.

Targeting tax professionals

The phishing campaign starts with emails that pretend to be clients sending the necessary documents to complete their return.

Buy JNews
ADVERTISEMENT

“I apologize not responding sooner; our individual tax return should be simple and not require much of your time,” reads a phishing email seen by Microsoft.

“I believe you would require a copy of our most recent year’s documents, such as W-2s, 1099s, mortages, interest, donations, medical investments, HSAs, and so on which I have uploaded below.”

Phishing email sent to tax preparers
Phishing email sent to tax preparers
Source: Microsoft

These phishing emails contain links that utilize click-tracking services to evade detection by security software, and ultimately lead to a file hosting site that downloads a ZIP archive.

This ZIP archive contains numerous files pretending to be PDF files for various tax forms but are actually Windows shortcuts.

Archive containing Windows shortcuts disguised as 2021 tax forms
Archive containing Windows shortcuts disguised as 2021 tax forms
Source: Microsoft

When double-clicked, these Windows shortcuts will execute PowerShell to download a heavily obfuscated VBS file from a remote host, which is saved to C:WindowsTasks and executed.

At the same time, the VBS script will download a decoy PDF file and open it in Microsoft Edge to avoid arousing suspicion by the targeted person.

Microsoft says that these VBS files will download and execute the GuLoader malware, which in turn, installs the Remcos remote access trojan.

Attack flow of phishing campaign
Attack flow of phishing campaign
Source: Microsoft

Remcos is a remote access trojan that threat actors commonly use in phishing campaigns to gain initial access to corporate networks.

Using this access, the threat actors can spread further through the network, stealing data and deploying other malware on a device.

Microsoft says that while phishing campaigns commonly use tax-related themes, this campaign is unusual as its only targets tax preparation firms and individuals.

“While social engineering lures like this one are common around Tax Day and other big topic current events, these campaigns are specific and targeted in a way that is uncommon.”

“The targets for this threat are exclusively organizations that deal with tax preparation, financial services, CPA and accounting firms, and professional service firms dealing in bookkeeping and tax.”

As accountants hold highly sensitive data for individuals and corporations, a data breach in this type of organization could significantly harm a large group of people.

As the initial loaders for the malware in this campaign are malicious files impersonating PDF files, we always recommend that users enable the display of file extensions in Windows so they can identify suspicious files.

Unfortunately, Windows shortcuts are a special file type that uses the .lnk file extension but does not show the file extension when displayed in File Explorer.

This behavior makes detecting that a file is a shortcut in disguise more difficult. However, listing files in File Explorer in ‘Details’ mode will show that it is Windows Shortcut, making it a bit easier to spot.

Ultimately, no one should click on links in emails or open attachments unless they confirm if they are sent from a legitimate contact. Otherwise, delete the email.

Share54Tweet34Pin12
Lawrence Abrams

Lawrence Abrams

Related Posts

Beware: Hackers now use OneNote attachments to spread malware
Cyber Security

New Horabot campaign takes over victim’s Gmail, Outlook accounts

June 1, 2023
Windows 11 will let you view phone photos in File Explorer
Cyber Security

Windows 11 will let you view phone photos in File Explorer

June 1, 2023
Latitude cyberattack leads to data theft at two service providers
Cyber Security

Harvard Pilgrim Health Care ransomware attack hits 2.5 million people

June 1, 2023
Apple fixes recently disclosed zero-days on older iPhones and iPads
Cyber Security

Russia says US hacked thousands of iPhones in iOS zero-click attacks

June 1, 2023
Hackers turn to Google search ads to push info-stealing malware
Cyber Security

Google triples rewards for Chrome sandbox escape chain exploits

June 1, 2023
OSV and the Vulnerability Life Cycle
Cyber Security

Announcing the Chrome Browser Full Chain Exploit Bonus

June 1, 2023

Recommended Stories

I grilled ChatGPT about Polygon’s [MATIC] price action, but it left me intrigued

I asked ChatGPT about what lies ahead for MATIC, it said…

May 21, 2023
Aurora infostealer malware increasingly adopted by cybergangs

Australians lost a record $3.1 billion to scams last year

April 18, 2023
Microsoft: Achilles macOS bug lets hackers bypass Gatekeeper

Apple’s first Rapid Security Response patch fails to install on iPhones

May 1, 2023

Popular Stories

  • New Python malware backdoors VMware ESXi servers for remote access

    Massive ESXiArgs ransomware attack targets VMware ESXi servers worldwide

    137 shares
    Share 55 Tweet 34
  • Facts and myths about the warriors who raided Europe and explored the New World

    137 shares
    Share 55 Tweet 34
  • Exploit released for actively abused ProxyNotShell Exchange bug

    137 shares
    Share 55 Tweet 34
  • New Windows Server updates cause domain controller freezes, restarts

    136 shares
    Share 54 Tweet 34
  • Bing Chat’s secret modes turn it into a personal assistant or friend

    136 shares
    Share 54 Tweet 34
Whats Current In

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Visit our landing page to see all features & demos.

LEARN MORE »

Recent Posts

  • XRP traders, know this about the ‘golden pocket’
  • New Horabot campaign takes over victim’s Gmail, Outlook accounts
  • LTC surprises investors with promising gains; this is what could happen next

Categories

  • Apple Computer
  • Blockchain
  • Cyber Security
  • Tech News
  • Venture Capital

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?