logo

Operation TaxShadow: Tax Phishing Hides In-Memory Malware

ID: 283d5e50-6118-5ecd-af4e-b89f95fe2880

STIX ID: report--283d5e50-6118-5ecd-af4e-b89f95fe2880

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

Author: Do Son

...
...

Operation TaxShadow is a sophisticated, multi-stage phishing campaign masquerading as government tax notices that distributes a ZIP archive containing a loader EXE, a malicious SbieDll.dll that installs API hooks and a Mersenne-Twister VM, and an encrypted SbieDll.bin which is reflectively loaded into memory; the malware uses DLL search-order hijacking, memory-only execution, WebSocket-based C2, proxy tunneling, and process injection (e.g., svchost.exe) to avoid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.