logo

Threat actors leverage tax season to deploy tax-themed phishing campaigns

ID: 3e710c8f-d46c-52bc-9f61-e35d451e8f68

STIX ID: report--3e710c8f-d46c-52bc-9f61-e35d451e8f68

Feed Name: Microsoft Security

Threat Score
78/100

Date Published: 2025-04-03

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft observed multiple tax-season phishing campaigns targeting U.S. organizations that used redirection (URL shorteners, QR codes, open redirectors) and legitimate services to evade detection and deliver loaders and RATs (BRc4, Latrodectus, GuLoader, Remcos, AHKBot) and to harvest credentials via RaccoonO365; one campaign is attributed to access broker Storm-0249. The blog provides detailed infection-chain descriptions, IOCs (domains, IPs, SHA-256 hashes), Sentinel hunting queries, and guidance for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.