Declaration trap: Crypto Drainers masquerading as European Tax Authorities
ID: 44beee8b-c2cf-5e7c-8a47-5bf9a97cb22c
STIX ID: report--44beee8b-c2cf-5e7c-8a47-5bf9a97cb22c
Feed Name: Group-IB Blog
Group-IB tracked an active 2025 phishing campaign targeting Dutch (and expanding to other European) crypto holders by impersonating Belastingdienst / MijnOverheid. Victims receive urgent tax-declaration emails that link to convincing government-themed phishing sites which collect personal data and either capture wallet seed phrases (exfiltrated to Telegram/admin panels) or use WalletConnect to present and have victims sign malicious transactions (Inferno Drainer), resulting in rapid wallet draining; the report provides sample scripts, hashes, and numerous domain IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
