logo

Cybercriminals Exploit URL Shorteners and QR Codes for Tax-Related Phishing Scams

ID: 797647aa-66ac-5f8e-a25c-775ff6f2272f

STIX ID: report--797647aa-66ac-5f8e-a25c-775ff6f2272f

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2025-04-04

Date Updated: 2026-04-13

Author: Mandvi

...
...

Microsoft observed large-scale tax-themed phishing campaigns using RaccoonO365 PhaaS and evasive delivery techniques (QR codes, URL shorteners, legitimate hosting) to steal credentials and deliver loaders and remote-access malware (Latrodectus, BruteRatel C4, GuLoader, Remcos). The campaigns targeted thousands of users and organizations, including accountants and CPAs, and employed social engineering plus anti-analysis malware features to increase success and persistence; defenders are advised to apply MFA, phishing-resistant auth, endpoint detection, and user education.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.