logo

Tax Season is Upon Us, and So Are the Scammers

ID: 8b86082d-85ab-51d9-bc65-6c759471e74e

STIX ID: report--8b86082d-85ab-51d9-bc65-6c759471e74e

Feed Name: Proofpoint Blog

Threat Score
70/100

Date Published: 2024-01-31

Date Updated: 2026-04-28

...
...

Proofpoint researchers report that TA576 has resumed tax-season campaigns targeting accounting and finance organizations in North America, using compromised email accounts and reply-to domains to send malicious Firebase URLs which redirect to zipped LNK shortcuts; execution chains leverage encoded PowerShell, SyncAppvPublishingServer.vbs LOLBAS injection, and Mshta/HTA to deploy the Parallax RAT, enabling credential theft, remote access, and potential lateral movement while using living-off-the-land techniques to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.