logo

Threat Actors are Targeting US Tax-Session with new Tactics of Stealerium-infostealer

ID: 84670c3b-422a-5ea3-8e92-1cde20510b3b

STIX ID: report--84670c3b-422a-5ea3-8e92-1cde20510b3b

Feed Name: Seqrite Blog

Threat Score
72/100

Date Published: 2025-04-30

Date Updated: 2026-04-30

Author: Dixit Panchal

...
...

Seqrite Labs discovered an active tax-season phishing campaign targeting U.S. citizens that uses deceptive .lnk attachments and nested Base64 PowerShell to fetch a PyInstaller-packed binary which stages a .NET infostealer (Stealerium v1.0.35). The report provides a full technical breakdown (execution chain, anti-analysis, mutex/hidden directories, browser/wallet/FTP/VPN/data theft, webcam/screenshot capture), ATT&CK mappings, IoCs (file hashes and C2 IPs), and recommended protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.