logo

Declaration trap: Crypto Drainers masquerading as European Tax Authorities

ID: 44beee8b-c2cf-5e7c-8a47-5bf9a97cb22c

STIX ID: report--44beee8b-c2cf-5e7c-8a47-5bf9a97cb22c

Feed Name: Group-IB Blog

Threat Score
70/100

Date Published: 2025-06-19

Date Updated: 2026-04-28

...
...

Group-IB tracked an active 2025 phishing campaign targeting Dutch (and expanding to other European) crypto holders by impersonating Belastingdienst / MijnOverheid. Victims receive urgent tax-declaration emails that link to convincing government-themed phishing sites which collect personal data and either capture wallet seed phrases (exfiltrated to Telegram/admin panels) or use WalletConnect to present and have victims sign malicious transactions (Inferno Drainer), resulting in rapid wallet draining; the report provides sample scripts, hashes, and numerous domain IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.