Phishing threats return ahead of tax season in the US

Hook on Keyboard
(Image credit: wk1003mike / Shutterstock)

As the Internal Revenue Service (IRS) has delayed the deadline for its annual Tax Day, US citizens have been given a bit more time to get their taxes in order. However, this delay has also given cybercriminals additional time to prepare their tax-themed phishing lures.

At the end of March, the IRS issued a security alert in which it warned of an ongoing email-based impersonation campaign targeting education institutions as well college students and staff with “.edu” email addresses. In addition to educational institutions, the cybersecurity firm Proofpoint has also observed similar threats targeting dozens of verticals from manufacturing to healthcare to energy.

While cybercriminals take advantage of tax season each year to launch tax scams to steal money and sensitive information, this year is particularly unique due to the fact that threat actors are combining their typical tax lures with healthcare and other pandemic-related lures.

So far in 2021, Proofpoint has observed over 30 tax-themed malicious email campaigns and more than 800,000 email messages, according to a new blog post from the company. These emails include attempts to compromise users' personal email accounts and steal their personal data. Proofpoint also observed multiple campaigns aligned with business email compromise activities that can be used to facilitate payroll fraud which can cost organizations millions.

Tax-themed phishing threats

The over 30 discrete campaigns observed by Proofpoint have targeted thousands of people from multiple threat actors that used malicious email lures associated with taxes, tax and refund support and government revenue entities. At least four different threat actor groups tracked by the firm have launched tax-themed malicious email campaigns in 2021.

Credential theft phishing attempts accounted for 40 percent of the campaigns and these can be used to target individuals or for email account takeovers. Remote Access Trojans (RAT) were used in 17 percent of the campaigns and while fewer campaigns featured RATs, they were far more popular in total message volume. 

Half of the tax-themed campaigns and related messages contained malware that is used to distribute the Remcos RAT which has extensive data theft and surveillance capabilities. Other tax-themed malware distribution campaigns observed by Proofpoint included Dridex, TrickBot and ZLoader.

Last year, cybercriminals increasingly used Excel 4.0 (XL4) macros to distribute malware and this trend has continued in 2021. Proofpoint observed a 500 percent increase in tax-themed email threat campaigns delivering weaponized XL4 Macros in just the first three months of this year.

To prevent falling victim to tax-themed phishing campaigns this tax season, Proofpoint recommends that users learn to spot malicious emails and report them. At the same time though, it is imperative that US citizens remember that the IRS will never contact you over email, text messages or social media and will instead send you a letter by mail.

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Beware, that Social Security email could be hiding dangerous malware
An iPhone sitting on a wooden table
Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes - how to stay safe
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Everything you need to know about phishing
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
Concept art representing cybersecurity principles
Cybercriminals cashing in on holiday sales rush
Close up of a business person using a smartphone.
Watch out, malicious PDF files are being used again in phishing attacks
Latest in Security
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Oracle
Oracle denies data breach after hacker claims to hold six million records
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
Latest in News
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening
A phone showing a ChatGPT app error message
ChatGPT was down for many – here's what happened
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired
A woman sitting in a chair looking at a Windows 11 laptop
It looks like Microsoft might have thought better about banishing Copilot AI shortcut from Windows 11
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard