216.73.216.6

When tax season becomes cyberattack season: Phishing and malware campaigns using tax-related lures

· Published 19/03/2026 15:28 · Modified 20/03/2026 08:17

Export JSON

Essential information

Published
19/03/2026 15:28
Modified
20/03/2026 08:17
Tags
2026-03-19 cpa targeting credential-theft datto irs impersonation malware phishing remote monitoring tools screenconnect simplehelp social engineering tax season
Related entities
2 observables, 12 techniques (mitre), 3 malware, 17 others

Description

During , threat actors exploit the urgency of time-sensitive tax-related emails to trick targets into opening malicious attachments, scanning QR codes, or following link chains. Recent campaigns identified by Microsoft Threat Intelligence use lures around W-2 forms, tax forms, and impersonation of government tax agencies and financial institutions. These campaigns aim to harvest credentials or deliver , often using -as-a-service platforms for convincing credential theft and MFA bypass. Notable tactics include using legitimate , targeting specific industries and roles like accountants, and employing sophisticated techniques. The campaigns leverage various file formats, legitimate infrastructure, and multiple user interactions to complicate detection.

External references