Security Brief: Threat Actors Take Taxes Into Account
Essential information
- Published
- 28/01/2025 17:19
- Modified
- 29/01/2025 17:32
- Tags
- 2025-01-28 asyncrat credential harvesting financial fraud government impersonation hmrc intuit malware delivery metastealer mygov revolut rhadamanthys tax-themed phishing venomrat xworm zgrat
- Related entities
- 12 techniques (mitre), 6 malware, 4 others
Description
Proofpoint researchers have identified an increase in campaigns and malicious domains impersonating tax agencies and financial organizations. This aligns with the annual increase in tax-related content observed from December through April. Phishing lures impersonate government agencies and financial services organizations involved in tax filing. Campaigns targeting the UK, US, Switzerland, and Australia have been observed, using various tactics such as credential harvesting, fraudulent payment requests, and malware delivery. Threat actors exploit tax themes to make their lures more convincing, especially during filing seasons. Organizations are advised to educate users about common techniques and lures used by attackers.