Emotet malware impersonates IRS as 2022 tax season approaches

A white padlock on a dark digital background.
(Image credit: Shutterstock.com)

As the 2022 tax season nears, numerous active phishing campaigns have been discovered impersonating the IRS to steal people’s sensitive data, and potentially - money.

One such campaign was just recently spotted by cybersecurity researchers from Cofense, which found threat actors pretending to be the Internal Revenue Service (IRS), sending out emails with tax forms and federal returns.

In most cases, the emails carry false 2021 Tax Return forms, W-9 forms, or other tax documents that are commonly being distributed this time of the year. These documents, either Word files, or Excel files, carry malicious macros, and if triggered, will download the Emotet malware.

TechRadar needs you!

We're looking at how our readers use VPNs with different devices so we can improve our content and offer better advice. This survey shouldn't take more than 60 seconds of your time. Thank you for taking part.

>> Click here to start the survey in a new window <<

Spreading ransomware

Emotet has multiple functions, with two most basic ones being - to spread to more machines via email; and to deliver stage-two malware. Cofense says that these days, Emotet is mostly used to deliver Cobalt Strike, ransomware payloads, or SystemBC remote access Trojan. When it infects a machine, it will try to weasel its way into the inbox, and use existing email threads to re-distribute itself without raising suspicion. 

Of these threats, ransomware seems to be the most obvious one, given that Emotet is being developed by the Conti Ransomware group.

The best way to protect against these attacks is to be vigilant when opening emails or downloading attachments. The IRS never sends unsolicited emails, and will only correspond through the postal service. 

When receiving emails with attachments, or links, it is important to double-check the sender’s name and address, because that’s often the first place where a red flag can be noticed. Also, typos, poor English, and a mismatch in visual identity, can also be clues to a potential phishing attack. And finally, hovering over a hyperlinked keyword in an email gives away its actual address.

Via: BleepingComputer

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Beware, that Social Security email could be hiding dangerous malware
Shutterstock.com / kanlaya wanon
Microsoft Teams abused in Russian email bombing ransomware campaign
linkedin
Watch out - that LinkedIn email could be a fake, laden with malware
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
An iPhone sitting on a wooden table
Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes - how to stay safe
Close up of a business person using a smartphone.
Watch out, malicious PDF files are being used again in phishing attacks
Latest in Security
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple H3C Magic routers hit by critical severity remote command injection, with no fix in sight
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Latest in News
Samsung Galaxy S25 from the front
The Now Bar on Samsung One UI 7 is about to get a lot more useful – and could soon match Live Activities on iOS
Netflix Ads
Netflix adds HDR10+ support – great news for Samsung TV owners, but don't expect LG and Sony to do the same any time soon
Klipsch Klipschorn AK7 in a room with lots of dark wood furniture and a bare brick wall
Klipsch just updated two of its most iconic stereo speaker designs, keeping these beautiful retro icons on your most-wanted list
FiiO FX17 IEMs
Our favorite budget audiophile brand unveils wired earbuds with 26(!) drivers, electrostatic units, USB-C ultra-Hi-Res Audio, and a not-so-budget price
Nvidia RTX 5080 against a yellow TechRadar background
RTX 5080 24GB version teased by MSI - is it time to admit that 16GB isn't enough for 4K?
A close up of the PlayStation symbol at the top of a PS5 Slim console with a white brick background
Sony has dropped a new PS5 update, improving activities and adding more emoji support