Hackers Use URL Shorteners and QR Codes in Tax-Themed Phishing Attacks
ID: c38d0e4c-2a02-5836-a89c-cab7747b33ca
STIX ID: report--c38d0e4c-2a02-5836-a89c-cab7747b33ca
Feed Name: GBHackers
During tax season, multiple sophisticated phishing campaigns leveraged PDF attachments containing QR codes and shortened URLs plus legitimate cloud services to redirect victims to fake login pages or downloaders; observed payloads include loaders and RATs (GuLoader, Latrodectus, Remcos), post-exploitation frameworks (BruteRatel C4), and credential-stealing techniques, with activity tied to RaccoonO365 PhaaS and Storm-0249. Microsoft observed thousands of targets and recommends user training, MFA, advanced email protections, and EDR to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
