logo

Tax Season Terror: Phishing Campaigns Weaponize Urgency to Deliver Remote Access Tools

ID: 69fcdaba-c036-5d3b-be0a-e637da4f4a7d

STIX ID: report--69fcdaba-c036-5d3b-be0a-e637da4f4a7d

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-24

Date Updated: 2026-04-23

Author: Ddos

...
...

Microsoft Threat Intelligence observed a surge in tax-season phishing campaigns that use PhaaS-driven, multi-stage redirection (Amazon SES tracking -> look-alike SmartVault domain) and Cloudflare bot checks to deliver a malicious repackaged ScreenConnect RAT named `TranscriptViewer5.1.exe`; the campaign targets accountants and taxpayers to harvest credentials, exfiltrate tax data, and pivot across networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.