Cybercriminals Exploit URL Shorteners and QR Codes for Tax-Related Phishing Scams
ID: 797647aa-66ac-5f8e-a25c-775ff6f2272f
STIX ID: report--797647aa-66ac-5f8e-a25c-775ff6f2272f
Feed Name: Cyber Press
Microsoft observed large-scale tax-themed phishing campaigns using RaccoonO365 PhaaS and evasive delivery techniques (QR codes, URL shorteners, legitimate hosting) to steal credentials and deliver loaders and remote-access malware (Latrodectus, BruteRatel C4, GuLoader, Remcos). The campaigns targeted thousands of users and organizations, including accountants and CPAs, and employed social engineering plus anti-analysis malware features to increase success and persistence; defenders are advised to apply MFA, phishing-resistant auth, endpoint detection, and user education.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
