logo

IRS-Themed Phishing Granting Threat Actors Remote Access

ID: 53968fbc-9e30-5f28-bfd6-eedd2017a4c1

STIX ID: report--53968fbc-9e30-5f28-bfd6-eedd2017a4c1

Feed Name: CISecurity.org Insights Blog

Threat Score
75/100

Date Published: 2026-03-24

Date Updated: 2026-04-19

...
...

CIS CTI describes an active IRS/SSA-themed phishing campaign leveraging TryCloudflare domains to automatically download RemotePC installers that give attackers full remote access to victim systems; the report includes observed URLs, sandbox confirmation, multiple related URLs, and IOCs, and urges SLTT organizations to increase vigilance and leverage MS-ISAC services for mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.