logo

Hackers Use URL Shorteners and QR Codes in Tax-Themed Phishing Attacks

ID: c38d0e4c-2a02-5836-a89c-cab7747b33ca

STIX ID: report--c38d0e4c-2a02-5836-a89c-cab7747b33ca

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2025-04-04

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

During tax season, multiple sophisticated phishing campaigns leveraged PDF attachments containing QR codes and shortened URLs plus legitimate cloud services to redirect victims to fake login pages or downloaders; observed payloads include loaders and RATs (GuLoader, Latrodectus, Remcos), post-exploitation frameworks (BruteRatel C4), and credential-stealing techniques, with activity tied to RaccoonO365 PhaaS and Storm-0249. Microsoft observed thousands of targets and recommends user training, MFA, advanced email protections, and EDR to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.