logo

Microsoft Warns IRS Phishing Hits 29,000 Users, Deploys RMM Malware

ID: 0df2f4a2-b7fd-5666-ae6b-a32818730acf

STIX ID: report--0df2f4a2-b7fd-5666-ae6b-a32818730acf

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-03-23

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Microsoft warns of large, ongoing phishing campaigns timed around U.S. tax season that use CPA/IRS and tax-themed lures, QR codes, and typosquatted domains to steal credentials and deliver remote access tools (ScreenConnect, Datto, SimpleHelp) and malware (Salat Stealer, RATs, cryptominers). Campaigns leverage Phishing-as-a-Service kits (Energy365, SneakyLog/Kratos), multi-vendor URL rewriting, abuse of legitimate services (Amazon SES, Cloudflare, Azure Monitor alerts), and deceptive pages to maintain persistence and evade detection; roughly 29,000 users in 10,000 organizations were impacted in one observed campaign. Organizations are advised to enforce 2FA, implement conditional access, monitor email/web traffic, and audit for unauthorized RMM usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.