logo

'Voldemort' Malware Curses Orgs Using Global Tax Authorities

ID: c45b0d68-6d1f-5684-84f2-3c9a5737e361

STIX ID: report--c45b0d68-6d1f-5684-84f2-3c9a5737e361

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-08-30

Date Updated: 2026-04-21

Author: Nathan Eddy, Contributing Writer

...
...

**Executive summary:** The "Voldemort" campaign is a global, active phishing campaign impersonating tax authorities to deliver a custom C backdoor that exfiltrates data and can drop additional payloads; it uses Google Sheets as a covert C2 channel and DLL sideloading via legitimate WebEx software, with Proofpoint reporting over 20,000 phishing messages and spikes of thousands in a single day.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.