Trend Report on Phishing Malware Impersonating the National Tax Service (NTS)
ID: c5328cd0-195b-5616-9a9f-aafbe92059e6
STIX ID: report--c5328cd0-195b-5616-9a9f-aafbe92059e6
Feed Name: ASEC
AhnLab ASEC observed a surge in 2024 phishing emails impersonating the National Tax Service that deliver diverse malware via attachments and links (HTML, VBS, PPT, DLL hijacking, CHM invoking mshta/PowerShell, EXE, LNK, SCR). Attackers use social engineering tied to tax season to distribute downloaders and info-stealers (GuLoader, Lokibot, AgentTesla, Formbook, Remcos, XWorm), employ persistence (Run registry, DLL hijacking), and host or fetch payloads from C2/Git resources; several MD5 hashes for samples are provided as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
