{"id":58420,"date":"2025-04-03T16:00:00","date_gmt":"2025-04-03T16:00:00","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\/"},"modified":"2025-04-03T16:00:00","modified_gmt":"2025-04-03T16:00:00","slug":"threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\/","title":{"rendered":"Threat actors leverage tax season to deploy tax-themed phishing campaigns"},"content":{"rendered":"<p>As Tax Day approaches in the United States on April 15, Microsoft has observed several phishing campaigns using tax-related themes for social engineering to steal credentials and deploy malware. These campaigns notably use redirection methods such as URL shorteners and QR codes contained in malicious attachments and abuse legitimate services like file-hosting services and business profile pages to avoid detection. These campaigns lead to phishing pages delivered via the RaccoonO365 phishing-as-a-service (PhaaS) platform, remote access trojans (RATs) like Remcos, and other malware like Latrodectus, BruteRatel C4 (BRc4), AHKBot, and GuLoader.<\/p>\n<p>Every year, threat actors use various social engineering techniques during tax season to steal personal and financial information, which can result in identity theft and monetary loss. These threat actors craft campaigns that mislead taxpayers into revealing sensitive information, making payments to fake services, or installing malicious payloads. Although these are well-known, longstanding techniques, they could still be highly effective if users and organizations don\u2019t use advanced anti-phishing solutions and conduct user awareness and training.&nbsp;<\/p>\n<p>In this blog, we share details on the different campaigns observed by Microsoft in the past several months leveraging the tax season for social engineering. This also includes additional recommendations to help users and organizations defend against tax-centric threats. Microsoft Defender for Office 365 blocks and identifies the malicious emails and attachments used in the observed campaigns. Microsoft Defender for Endpoint also detects and blocks a variety of threats and malicious activities related but not limited to the tax threat landscape. Additionally, the <a href=\"https:\/\/www.irs.gov\/privacy-disclosure\/report-phishing\">United States Internal Revenue Service (IRS) does not initiate contact<\/a> with taxpayers by email, text messages or social media to request personal or financial information.<\/p>\n<h2 class=\"wp-block-heading\" id=\"bruteratel-c4-and-latrodectus-delivered-in-tax-and-irs-themed-phishing-emails\">BruteRatel C4 and Latrodectus delivered in tax and IRS-themed phishing emails<\/h2>\n<p>On February 6, 2025, Microsoft observed a phishing campaign that involved several thousand emails targeting the United States. The campaign used tax-themed emails that attempted to deliver the red-teaming tool BRc4 and Latrodectus malware.&nbsp;Microsoft attributes this campaign to Storm-0249, an access broker active since 2021 and known for distributing, at minimum, BazaLoader, IcedID, Bumblebee, and Emotet malware. The following lists the details of the phishing emails used in the campaign:<\/p>\n<p>Example email subjects:<\/p>\n<ul class=\"wp-block-list\">\n<li>Notice: IRS Has Flagged Issues with Your Tax Filing<\/li>\n<li>Unusual Activity Detected in Your IRS Filing<\/li>\n<li>Important Action Required: IRS Audit<\/li>\n<\/ul>\n<p>Example PDF attachment names:<\/p>\n<ul class=\"wp-block-list\">\n<li>lrs_Verification_Form_1773.pdf<\/li>\n<li>lrs_Verification_Form_2182.pdf<\/li>\n<li>lrs_Verification_Form_222.pdf<\/li>\n<\/ul>\n<p>The emails contained a PDF attachment with an embedded DoubleClick URL that redirected users to a Rebrandly URL shortening link. That link in turn redirected the browser to a landing site that displayed a fake DocuSign page hosted on a domain masquerading as DocuSign. When users clicked the Download button on the landing page, the outcome depended on whether their system and IP address were allowed to access the next stage based on filtering rules set up by the threat actor:<\/p>\n<ul class=\"wp-block-list\">\n<li><strong>If access was permitted<\/strong>, the user received a JavaScript file from Firebase, a platform sometimes misused by cybercriminals to host malware. If executed, this JavaScript file downloaded a Microsoft Software Installer (MSI) containing BRc4 malware, which then installed Latrodectus, a malicious tool used for further attacks.<\/li>\n<li><strong>If access was restricted<\/strong>, the user received a benign PDF file from <em>royalegroupnyc[.]com<\/em>. This served as a decoy to evade detection by security systems.<\/li>\n<\/ul>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/04\/image.webp\" alt=\"Screenshot of a sample phishing email claiming to be from the IRS\" class=\"wp-image-138254 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/04\/image.webp\"><figcaption class=\"wp-element-caption\">Figure 1. Sample phishing email that claims to be from the IRS<\/figcaption><\/figure>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/04\/image-1.webp\" alt=\"Screenshot of a fake DocuSign page that leads to a malicious PDF file.\" class=\"wp-image-138255 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/04\/image-1.webp\"><figcaption class=\"wp-element-caption\">Figure 2. PDF attachment masquerading as a DocuSign document<\/figcaption><\/figure>\n<p>Latrodectus is a loader primarily used for initial access and payload delivery. It features dynamic command-and-control (C2) configurations, anti-analysis features such as minimum process count and network adapter check, C2 check-in behavior that splits POST data between the Cookie header and POST data. Latrodectus 1.9, the malware\u2019s latest evolution first observed in February 2025, reintroduced scheduled tasks for persistence and added the ability to run Windows commands via the command prompt.<\/p>\n<p>BRc4 is an advanced adversary simulation and red-teaming framework designed to bypass modern security defenses, but it has also been exploited by threat actors for post-exploitation activities and C2 operations.<\/p>\n<h2 class=\"wp-block-heading\" id=\"phishing-email-with-qr-code-in-a-pdf-links-to-raccoono365-infrastructure\">Phishing email with QR code in a PDF links to RaccoonO365 infrastructure<\/h2>\n<p>Between February 12 and 28, 2025, tax-themed phishing emails were sent to over 2,300 organizations, mostly in the United States in the engineering, IT, and consulting sectors. The emails had an empty body but contained a PDF attachment with a QR code and subjects indicating that the documents needed to be signed by the recipient. The QR code pointed to a hyperlink associated with a RaccoonO365 domain: s<em>hareddocumentso365cloudauthstorage[.]com<\/em>. The URL included the recipient email as a query string parameter, so the PDF attachments were all unique. RaccoonO365 is a PhaaS platform that provides phishing kits that mimic Microsoft 365 sign-in pages to steal credentials. The URL was likely a phishing page used to collect the targeted user\u2019s credentials.<\/p>\n<p>The emails were sent with a variety of display names, which are the names that recipients see in their inboxes, to make the emails appear as if they came from an official source. The following display names were observed in these campaigns:<\/p>\n<ul class=\"wp-block-list\">\n<li>EMPLOYEE TAX REFUND REPORT<\/li>\n<li>Project Funding Request Budget Allocation<\/li>\n<li>Insurance Payment Schedule Invoice Processing<\/li>\n<li>Client Contract Negotiation Service Agreement<\/li>\n<li>Adjustment Review Employee Compensation<\/li>\n<li>Tax Strategy Update Campaign Goals<\/li>\n<li>Team Bonus Distribution Performance Review<\/li>\n<li>proposal request<\/li>\n<li>HR|Employee Handbooks<\/li>\n<\/ul>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/04\/image-2.webp\" alt=\"Screenshot of a PDF file that features a QR code purporting to lead to a file named Q1 Tax Refundreport.pdf\" class=\"wp-image-138256 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/04\/image-2.webp\"><figcaption class=\"wp-element-caption\">Figure 3. Screenshot of the opened PDF with the QR code<\/figcaption><\/figure>\n<h2 class=\"wp-block-heading\" id=\"ahkbot-delivered-in-irs-themed-phishing-emails\">AHKBot delivered in IRS-themed phishing emails<\/h2>\n<p>On February 13, 2025, Microsoft observed a campaign using an IRS-themed email that targeted users in the United States. The email\u2019s subject was <em>IRS Refund Eligibility Notification<\/em> and the sender was <em>jessicalee@eboxsystems[.]com<\/em>.<\/p>\n<p>The email contained a hyperlink that directed users to download a malicious Excel file. The link (<em>hxxps:\/\/business.google[.]com\/website_shared\/launch_bw[.]html?f=hxxps:\/\/historyofpia[.]com\/Tax_Refund_Eligibility_Document[.]xlsm<\/em>) abused an open redirector on what appeared to be a legitimate Google Business page. It redirected users to <em>historyofpia[.]com, <\/em>which was likely compromised to host the malicious Excel file. If the user opened the Excel file, they were prompted to enable macros, and if the user enabled macros, a malicious MSI file was downloaded and run.<\/p>\n<p>The MSI file contained two files. The first file, <em>AutoNotify.exe<\/em>, is a legitimate copy of the executable used to run AutoHotKey script files. The second file, <em>AutoNotify.ahk<\/em>, is an AHKBot Looper script which is a simple infinite loop that receives and runs additional AutoHotKey scripts. The AHKBot Looper was in turn observed downloading the Screenshotter module, which includes code to capture screenshots from the compromised device. Both Looper and Screenshotter used the C2 IP address 181.49.105[.]59 to receive commands and upload screenshots.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/04\/image-3.webp\" alt=\"Screenshot of an email claiming to be from the IRS. The email contains a link to a malicious Excel file. \" class=\"wp-image-138257 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/04\/image-3.webp\"><figcaption class=\"wp-element-caption\">Figure 4. Screenshot of the email showing the link to download a malicious Excel file<\/figcaption><\/figure>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/04\/image-4.webp\" alt=\"Screenshot of macro code that installs a malicious MSI file\" class=\"wp-image-138258 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/04\/image-4.webp\"><figcaption class=\"wp-element-caption\">Figure 5. Macro code to install the malicious MSI file from hxxps:\/\/acusense[.]ae\/umbrella\/<\/figcaption><\/figure>\n<h2 class=\"wp-block-heading\" id=\"guloader-and-remcos-delivered-in-tax-themed-phishing-emails\">GuLoader and Remcos delivered in tax-themed phishing emails<\/h2>\n<p>On March 3, 2025, Microsoft observed a tax-themed phishing campaign targeting CPAs and accountants in the United States, attempting to deliver GuLoader and Remcos malware. The campaign, which consisted of less than 100 emails, began with a benign rapport-building email from a fake persona asking for tax filing services due to negligence by a previous CPA. If the recipient replied, they would then receive a second email with the malicious PDF. This technique increases the click rates on the malicious payloads due to the established rapport between attacker and recipient.<\/p>\n<p>The malicious PDF attachment contained an embedded URL. If the attachment was opened and the URL clicked, a ZIP file was downloaded from Dropbox. The ZIP file contained various <em>.lnk<\/em> files set up to mimic tax documents. If launched by the user, the <em>.lnk<\/em> file uses PowerShell to download a PDF and a <em>.bat<\/em> file. The <em>.bat<\/em> file in turn downloaded the GuLoader executable, which then installed Remcos.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/04\/image-5.webp\" alt=\"Screenshot of a phishing email wherein the sender requests for tax filing services from the target. \" class=\"wp-image-138260 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/04\/image-5.webp\"><figcaption class=\"wp-element-caption\">Figure 6. Sample phishing email shows the original benign request for tax filing services, followed by another email containing a malicious PDF attachment if the target replies.<\/figcaption><\/figure>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" alt=\"Screenshot of a PDF file that features a blue &quot;download&quot; button in the middle. The said button links to the download of a malicious payload.\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/04\/image-6.webp\" class=\"wp-image-138261 webp-format\" srcset data-orig-alt=\"A close up of a web page\"><figcaption class=\"wp-element-caption\">Figure 7. The PDF attachment contains a prominent blue \u201cDownload\u201d button that links to download of the malicious payload. The button is overlaid over a blurred background mimicking a \u201cW-2\u201d tax form, which further contributes to the illusion of the attachment being a legitimate tax file.<\/figcaption><\/figure>\n<p><strong>GuLoader<\/strong> is a highly evasive malware downloader that leverages encrypted shellcode, process injection, and cloud-based hosting services to deliver various payloads, including RATs and infostealers. It employs multiple anti-analysis techniques, such as sandbox detection and API obfuscation, to bypass security defenses and ensure successful payload execution.<\/p>\n<p><strong>Remcos<\/strong> is a RAT that provides attackers with full control over compromised systems through keylogging, screen capturing, and process manipulation while employing stealth techniques to evade detection.<\/p>\n<h2 class=\"wp-block-heading\" id=\"mitigation-and-protection-guidance\">Mitigation and protection guidance<\/h2>\n<p>Microsoft recommends the following mitigations to reduce the impact of this threat.<\/p>\n<ul class=\"wp-block-list\">\n<li>Educate users about&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/business\/security-101\/what-is-email-security\">protecting personal and business information<\/a>&nbsp;in social media, filtering unsolicited communication, identifying lure links in phishing emails, and reporting reconnaissance attempts and other suspicious activity.<\/li>\n<li>Turn on&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-office-365\/zero-hour-auto-purge\">Zero-hour auto purge (ZAP)<\/a>&nbsp;in Defender for Office 365 to quarantine sent mail in response to newly-acquired threat intelligence and retroactively neutralize malicious phishing, spam, or malware messages that have already been delivered to mailboxes.<\/li>\n<li>Pilot and deploy&nbsp;<a href=\"https:\/\/learn.microsoft.com\/azure\/active-directory\/authentication\/concept-authentication-methods?ocid=magicti_ta_learndoc\">phishing-resistant authentication methods<\/a>&nbsp;for users.<\/li>\n<li>Enforce multifactor authentication (MFA) on all accounts, remove users excluded from MFA, and strictly&nbsp;<a href=\"https:\/\/learn.microsoft.com\/azure\/active-directory\/identity-protection\/howto-identity-protection-configure-mfa-policy?ocid=magicti_ta_learndoc\">require MFA<\/a>&nbsp;from all devices in all locations at all times.<\/li>\n<li>Implement&nbsp;Entra ID&nbsp;<a href=\"https:\/\/learn.microsoft.com\/azure\/active-directory\/authentication\/concept-authentication-strengths?ocid=magicti_ta_learndoc\">Conditional Access authentication strength<\/a>&nbsp;to require phishing-resistant authentication for employees and external users for critical apps.<\/li>\n<li>Encourage users to use Microsoft Edge and other web browsers that support&nbsp;<a href=\"https:\/\/learn.microsoft.com\/deployedge\/microsoft-edge-security-smartscreen?ocid=magicti_ta_learndoc\">Microsoft Defender SmartScreen<\/a>, which identifies and blocks malicious websites including phishing sites, scam sites, and sites that contain exploits and host malware.<\/li>\n<li>Educate users about using the browser URL navigator to validate that upon clicking a link in search results they have arrived at an expected legitimate domain.<\/li>\n<li>Enable&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/enable-network-protection\">network protection<\/a>&nbsp;to prevent applications or users from accessing malicious domains and other malicious content on the internet.<\/li>\n<li>Configure Microsoft Defender for Office 365 to&nbsp;<a href=\"https:\/\/learn.microsoft.com\/microsoft-365\/security\/office-365-security\/safe-links-about?ocid=magicti_ta_learndoc\">recheck links on click<\/a>. Safe Links provides URL scanning and rewriting of inbound email messages in mail flow and time-of-click verification of URLs and links in email messages, other Microsoft Office applications such as Teams, and other locations such as SharePoint Online. Safe Links scanning occurs in addition to the regular&nbsp;<a href=\"https:\/\/learn.microsoft.com\/microsoft-365\/security\/office-365-security\/anti-spam-protection-about?ocid=magicti_ta_learndoc\">anti-spam<\/a>&nbsp;and&nbsp;<a href=\"https:\/\/learn.microsoft.com\/microsoft-365\/security\/office-365-security\/anti-malware-protection-about?ocid=magicti_ta_learndoc\">anti-malware<\/a>&nbsp;protection in inbound email messages in Microsoft Exchange Online Protection (EOP). Safe Links scanning can help protect your organization from malicious links that are used in phishing and other attacks.<\/li>\n<li>Turn on&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/enable-cloud-protection-microsoft-defender-antivirus\">cloud-delivered protection<\/a>&nbsp;in Microsoft Defender Antivirus or the equivalent for your antivirus product to cover rapidly evolving attacker tools and techniques. Cloud-based machine learning protections block a huge majority of new and unknown variants.<\/li>\n<li>Enable&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/automated-investigations\">investigation and remediation<\/a>&nbsp;in full automated mode to allow Defender for Endpoint to take immediate action on alerts to resolve breaches, significantly reducing alert volume.<\/li>\n<li>Run&nbsp;<a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/edr-in-block-mode\">endpoint detection and response (EDR) in block mode<\/a>, so that Defender for Endpoint can block malicious artifacts, even when your non-Microsoft antivirus doesn\u2019t detect the threat or when Microsoft Defender Antivirus is running in passive mode. EDR in block mode works behind the scenes to remediate malicious artifacts detected post-breach.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\" id=\"microsoft-defender-xdr-detections\">Microsoft Defender XDR detections<\/h2>\n<p>Microsoft Defender XDR customers can refer to the list of applicable detections below. Microsoft Defender XDR coordinates detection, prevention, investigation, and response across endpoints, identities, email, apps to provide integrated protection against attacks like the threat discussed in this blog.<\/p>\n<p>Customers with provisioned access can also use <a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/security-copilot-in-microsoft-365-defender\">Microsoft Security Copilot in Microsoft Defender<\/a> to investigate and respond to incidents, hunt for threats, and protect their organization with relevant threat intelligence.<\/p>\n<h3 class=\"wp-block-heading\" id=\"microsoft-defender-antivirus\">Microsoft Defender Antivirus<\/h3>\n<p>Microsoft Defender Antivirus detects threat components used in the campaigns shared in this blog as the following:<\/p>\n<h3 class=\"wp-block-heading\" id=\"microsoft-defender-for-endpoint\">Microsoft Defender for Endpoint<\/h3>\n<p>The following alerts might indicate threat activity associated with this threat. These alerts, however, can be triggered by unrelated threat activity and are not monitored in the status cards provided with this report.<\/p>\n<ul class=\"wp-block-list\">\n<li>Possible Latrodectus activity<\/li>\n<li>Brute Ratel toolkit related behavior<\/li>\n<li>A file or network connection related to ransomware-linked actor Storm-0249 detected<\/li>\n<li>Suspicious phishing activity detected<\/li>\n<\/ul>\n<h3 class=\"wp-block-heading\" id=\"microsoft-defender-for-office-365\">Microsoft Defender for Office 365<\/h3>\n<p>Microsoft Defender for Office 365 offers enhanced solutions for blocking and identifying malicious emails. These alerts, however, can be triggered by unrelated threat activity.<\/p>\n<ul class=\"wp-block-list\">\n<li>A potentially malicious URL click was detected&nbsp;<\/li>\n<li>Email messages containing malicious URL removed after delivery<\/li>\n<li>Email messages removed after delivery<\/li>\n<li>A user clicked through to a potentially malicious URL<\/li>\n<li>Suspicious email sending patterns detected<\/li>\n<li>Email reported by user as malware or phish<\/li>\n<\/ul>\n<p>Defender for Office 365 also detects the malicious PDF attachments used in the phishing campaign launched by Storm-0249.<\/p>\n<h2 class=\"wp-block-heading\" id=\"microsoft-security-copilot\">Microsoft Security Copilot<\/h2>\n<p>Security Copilot customers can use the standalone experience to <a href=\"https:\/\/learn.microsoft.com\/copilot\/security\/prompting-security-copilot#create-your-own-prompts\">create their own prompts<\/a> or run the following <a href=\"https:\/\/learn.microsoft.com\/copilot\/security\/using-promptbooks\">pre-built promptbooks<\/a> to automate incident response or investigation tasks related to this threat:<\/p>\n<ul class=\"wp-block-list\">\n<li>Incident investigation<\/li>\n<li>Microsoft User analysis<\/li>\n<li>Threat actor profile<\/li>\n<li>Threat Intelligence 360 report based on MDTI article<\/li>\n<li>Vulnerability impact assessment<\/li>\n<\/ul>\n<p>Note that some promptbooks require access to plugins for Microsoft products such as Microsoft Defender XDR or Microsoft Sentinel.<\/p>\n<h2 class=\"wp-block-heading\" id=\"threat-intelligence-reports\">Threat intelligence reports<\/h2>\n<p>Microsoft customers can use the following reports in Microsoft products to get the most up-to-date information about the threat actor, malicious activity, and techniques discussed in this blog. These reports provide the intelligence, protection information, and recommended actions to prevent, mitigate, or respond to associated threats found in customer environments.<\/p>\n<h3 class=\"wp-block-heading\" id=\"microsoft-defender-threat-intelligence\">Microsoft Defender Threat Intelligence<\/h3>\n<p>Microsoft Security Copilot customers can also use the <a href=\"https:\/\/learn.microsoft.com\/defender\/threat-intelligence\/security-copilot-and-defender-threat-intelligence?bc=%2Fsecurity-copilot%2Fbreadcrumb%2Ftoc.json&amp;toc=%2Fsecurity-copilot%2Ftoc.json#turn-on-the-security-copilot-integration-in-defender-ti\">Microsoft Security Copilot integration<\/a> in Microsoft Defender Threat Intelligence, either in the Security Copilot standalone portal or in the <a href=\"https:\/\/learn.microsoft.com\/defender\/threat-intelligence\/using-copilot-threat-intelligence-defender-xdr\">embedded experience<\/a> in the Microsoft Defender portal to get more information about this threat actor.<\/p>\n<h2 class=\"wp-block-heading\" id=\"hunting-queries\">Hunting queries<\/h2>\n<h3 class=\"wp-block-heading\" id=\"microsoft-sentinel\">Microsoft Sentinel<\/h3>\n<p>Microsoft Sentinel customers can use the TI Mapping analytics (a series of analytics all prefixed with \u2018TI map\u2019) to automatically match the malicious domain indicators mentioned in this blog post with data in their workspace. If the TI Map analytics are not currently deployed, customers can install the Threat Intelligence solution from the <a href=\"https:\/\/learn.microsoft.com\/azure\/sentinel\/sentinel-solutions-deploy\">Microsoft Sentinel Content Hub<\/a> to have the analytics rule deployed in their Sentinel workspace.<\/p>\n<p>Furthermore, listed below are some sample queries utilizing <a href=\"https:\/\/learn.microsoft.com\/azure\/sentinel\/normalization\">Sentinel ASIM Functions<\/a> for threat hunting across both Microsoft first-party and third-party data sources.<\/p>\n<p>Hunt normalized Network Session events using the ASIM unifying parser <em>_Im_NetworkSession<\/em> for IOCs:<\/p>\n<div class=\"wp-block-syntaxhighlighter-code \" readability=\"18\">\n<pre class=\"brush: plain; auto-links: false; gutter: false; title: ; quick-code: false; notranslate\" title>\nlet lookback = 7d;\nlet ioc_ip_addr = dynamic([\"181.49.105.59 \"]); _Im_NetworkSession(starttime=todatetime(ago(lookback)), endtime=now())\n| where DstIpAddr in (ioc_ip_addr) | summarize imNWS_mintime=min(TimeGenerated), imNWS_maxtime=max(TimeGenerated), EventCount=count() by SrcIpAddr, DstIpAddr, DstDomain, Dvc, EventProduct, EventVendor\n<\/pre>\n<\/div>\n<p>Hunt normalized File events using the ASIM unifying parser <em>imFileEvent<\/em> for IOCs:<\/p>\n<div class=\"wp-block-syntaxhighlighter-code \" readability=\"22\">\n<pre class=\"brush: plain; auto-links: false; gutter: false; title: ; quick-code: false; notranslate\" title>\nlet ioc_sha_hashes=dynamic([\"fe0b2e0fe7ce26ae398fe6c36dae551cb635696c927761738f040b581e4ed422\",\"bb3b6262a288610df46f785c57d7f1fa0ebc75178c625eaabf087c7ec3fccb6a\",\"9728b7c73ef25566cba2599cb86d87c360db7cafec003616f09ef70962f0f6fc\", \"3c482415979debc041d7e4c41a8f1a35ca0850b9e392fecbdef3d3bc0ac69960\",\"165896fb5761596c6f6d80323e4b5804e4ad448370ceaf9b525db30b2452f7f5\",\"a31ea11c98a398f4709d52e202f3f2d1698569b7b6878572fc891b8de56e1ff7\", \"a1b4db93eb72a520878ad338d66313fbaeab3634000fb7c69b1c34c9f3e17727\",\"0b22a0d84afb8bc4426ac3882a5ecd2e93818a2ea62d4d5cbae36d942552a36a\",\"4d5839d70f16e8f4f7980d0ae1758bb5a88b061fd723ea4bf32b4b474c222bec\",\"9bffe9add38808b3f6021e6d07084a06300347dd5d4b7e159d97e949735cff1e\"]); imFileEvent | where SrcFileSHA256 in (ioc_sha_hashes) or TargetFileSHA256 in (ioc_sha_hashes) | extend AccountName = tostring(split(User, @'\\')[1]), AccountNTDomain = tostring(split(User, @'\\')[0]) | extend AlgorithmType = \"SHA256\"\n<\/pre>\n<\/div>\n<p>&nbsp;Hunt normalized Web Session events using the ASIM unifying parser <em>_Im_WebSession<\/em> for IOCs:<\/p>\n<div class=\"wp-block-syntaxhighlighter-code \" readability=\"25\">\n<pre class=\"brush: plain; auto-links: false; gutter: false; title: ; quick-code: false; notranslate\" title>\nlet lookback = 7d;\nlet ioc_domains = dynamic([\"slgndocline.onlxtg.com \", \"cronoze.com \", \"muuxxu.com \", \"proliforetka.com \", \"porelinofigoventa.com \", \"shareddocumentso365cloudauthstorage.com\", \"newsbloger1.duckdns.org\"]); _Im_WebSession (starttime=ago(lookback), eventresult='Success', url_has_any=ioc_domains) | summarize imWS_mintime=min(TimeGenerated), imWS_maxtime=max(TimeGenerated), EventCount=count() by SrcIpAddr, DstIpAddr, Url, Dvc, EventProduct, EventVendor <\/pre>\n<\/div>\n<p>In addition to the above, Sentinel users can also leverage the following queries, which may be relevant to the content of this blog.<\/p>\n<h2 class=\"wp-block-heading\" id=\"indicators-of-compromise\">Indicators of compromise<\/h2>\n<p><strong>BruteRatel C4 and Lactrodectus infection chain<\/strong><\/p>\n<figure class=\"wp-block-table table\">\n<table class=\"has-fixed-layout\">\n<tbody readability=\"13.5\">\n<tr>\n<td><strong>Indicator<\/strong><\/td>\n<td><strong>Type<\/strong><\/td>\n<td><strong>Description<\/strong><\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>9bffe9add38808b3f6021e6d07084a06300347dd5d4b7e159d97e949735cff1e<\/td>\n<td>SHA-256<\/td>\n<td><em>lrs_Verification_Form_1730.pdf<\/em><\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>0b22a0d84afb8bc4426ac3882a5ecd2e93818a2ea62d4d5cbae36d942552a36a<\/td>\n<td>SHA-256<\/td>\n<td><em>Irs_verif_form_2025_214859.js<\/em><em><\/em><\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>4d5839d70f16e8f4f7980d0ae1758bb5a88b061fd723ea4bf32b4b474c222bec<\/td>\n<td>SHA-256<\/td>\n<td><em>bars.msi<\/em><em><\/em><\/td>\n<\/tr>\n<tr readability=\"5\">\n<td>a1b4db93eb72a520878ad338d66313fbaeab3634000fb7c69b1c34c9f3e17727<\/td>\n<td>SHA-256<\/td>\n<td>BRc4, filename: <em>nvidiamast.dll<\/em><\/td>\n<\/tr>\n<tr readability=\"4\">\n<td><em>hxxp:\/\/rebrand[.]ly\/243eaa<\/em><\/td>\n<td>Domain name<\/td>\n<td>URL shortener to load fake DocuSign page<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td><em>slgndocline.onlxtg[.]com<\/em><\/td>\n<td>Domain name<\/td>\n<td>Domain used to host fake DocuSign page<\/td>\n<\/tr>\n<tr>\n<td><em>cronoze[.]com<\/em><\/td>\n<td>Domain name<\/td>\n<td>BRc4 C2<\/td>\n<\/tr>\n<tr>\n<td><em>muuxxu[.]com<\/em><\/td>\n<td>Domain name<\/td>\n<td>BRc4 C2<\/td>\n<\/tr>\n<tr>\n<td><em>proliforetka[.]com<\/em><\/td>\n<td>Domain name<\/td>\n<td>Latrodectus C2<\/td>\n<\/tr>\n<tr>\n<td><em>porelinofigoventa[.]com<\/em><\/td>\n<td>Domain name<\/td>\n<td>Latrodectus C2<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td><em>hxxp:\/\/slgndocline.onlxtg[.]com\/87300038978\/<\/em><\/td>\n<td>URL<\/td>\n<td>Fake DocuSign URL<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td><em>hxxps:\/\/rosenbaum[.]live\/bars.php<\/em><\/td>\n<td>URL<\/td>\n<td>JavaScript downloading MSI<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p><strong>RaccoonO365<\/strong><\/p>\n<figure class=\"wp-block-table table\">\n<table class=\"has-fixed-layout\">\n<tbody readability=\"1\">\n<tr>\n<td><strong>Indicator<\/strong><\/td>\n<td><strong>Type<\/strong><\/td>\n<td><strong>Description<\/strong><\/td>\n<\/tr>\n<tr readability=\"2\">\n<td><em>shareddocumentso365cloudauthstorage[.]com<\/em><em><\/em><\/td>\n<td>Domain name<\/td>\n<td>RaccoonO365 domain<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p><strong>AHKBot<\/strong><strong><\/strong><\/p>\n<figure class=\"wp-block-table table\">\n<table class=\"has-fixed-layout\">\n<tbody readability=\"12.5\">\n<tr>\n<td><strong>Indicator<\/strong><\/td>\n<td><strong>Type<\/strong><\/td>\n<td><strong>Description<\/strong><\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>a31ea11c98a398f4709d52e202f3f2d1698569b7b6878572fc891b8de56e1ff7<\/td>\n<td>SHA-256<\/td>\n<td><em>Tax_Refund_Eligibility_Document.xlsm<\/em><\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>165896fb5761596c6f6d80323e4b5804e4ad448370ceaf9b525db30b2452f7f5<\/td>\n<td>SHA-256<\/td>\n<td><em>umbrella.msi<\/em><em><\/em><\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>3c482415979debc041d7e4c41a8f1a35ca0850b9e392fecbdef3d3bc0ac69960<\/td>\n<td>SHA-256<\/td>\n<td><em>AutoNotify.ahk<\/em><em><\/em><\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>9728b7c73ef25566cba2599cb86d87c360db7cafec003616f09ef70962f0f6fc<\/td>\n<td>SHA-256<\/td>\n<td>AHKBot Screenshotter module<\/td>\n<\/tr>\n<tr readability=\"5\">\n<td><em>hxxps:\/\/business.google[.]com\/website_shared\/launch_bw.html?f=hxxps:\/\/historyofpia[.]com\/Tax_Refund_Eligibility_Document.xlsm<\/em><\/td>\n<td>URL<\/td>\n<td>URL redirecting to URL hosting malicious Excel file<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td><em>hxxps:\/\/historyofpia[.]com\/Tax_Refund_Eligibility_Document.xlsm<\/em><\/td>\n<td>URL<\/td>\n<td>URL hosting malicious Excel file<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td><em>hxxps:\/\/acusense[.]ae\/umbrella\/<\/em><\/td>\n<td>URL<\/td>\n<td>URL in macro that hosted the malicious MSI file<\/td>\n<\/tr>\n<tr>\n<td>181.49.105[.]59<\/td>\n<td>IP address<\/td>\n<td>AHKBot C2<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p><strong>Remcos<\/strong><\/p>\n<figure class=\"wp-block-table table\">\n<table class=\"has-fixed-layout\">\n<tbody readability=\"5.5\">\n<tr>\n<td><strong>Indicator<\/strong><\/td>\n<td><strong>Type<\/strong><\/td>\n<td><strong>Description<\/strong><\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>bb3b6262a288610df46f785c57d7f1fa0ebc75178c625eaabf087c7ec3fccb6a<\/td>\n<td>SHA-256<\/td>\n<td><em>2024 Tax Document_Copy (1).pdf<\/em><\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>fe0b2e0fe7ce26ae398fe6c36dae551cb635696c927761738f040b581e4ed422<\/td>\n<td>SHA-256<\/td>\n<td><em>2024 Tax Document.zip<\/em><em><\/em><\/td>\n<\/tr>\n<tr readability=\"3\">\n<td><em>hxxps<\/em><em>:\/\/www.dropbox[.]com\/scl\/fi\/ox2fv884k4mhzv05lf4g1\/2024-Tax-Document.zip?rlkey=fjtynsx5c5ow59l4zc1nsslfi&amp;st=gvfamzw3&amp;dl=1<\/em><em><\/em><\/td>\n<td>URL<\/td>\n<td>URL in PDF<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td><em>newsbloger1.duckdns[.]org<\/em><em><\/em><\/td>\n<td>Domain name<\/td>\n<td>Remcos C2<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\" id=\"references\">References<\/h2>\n<h2 class=\"wp-block-heading\" id=\"learn-more\">Learn more<\/h2>\n<p>For the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog:&nbsp;<a href=\"https:\/\/aka.ms\/threatintelblog\">https:\/\/aka.ms\/threatintelblog<\/a>.<\/p>\n<p>To get notified about new publications and to join discussions on social media, follow us on LinkedIn at <a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-threat-intelligence\">https:\/\/www.linkedin.com\/showcase\/microsoft-threat-intelligence<\/a>, and on X (formerly Twitter) at&nbsp;<a href=\"https:\/\/x.com\/MsftSecIntel\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/x.com\/MsftSecIntel<\/a>.<\/p>\n<p>To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat Intelligence podcast: <a href=\"https:\/\/thecyberwire.com\/podcasts\/microsoft-threat-intelligence\">https:\/\/thecyberwire.com\/podcasts\/microsoft-threat-intelligence<\/a>.<\/p>\n<p> READ MORE <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/04\/03\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As Tax Day approaches in the United States on April 15, Microsoft has detected several tax-themed phishing campaigns employing various tactics. These campaigns use malicious hyperlinks and attachments to deliver credential phishing and malware including RaccoonO365, AHKBot, Latrodectus, BruteRatel C4 (BRc4), and Remcos.<br \/>\nThe post Threat actors leverage tax season to deploy tax-themed phishing campaigns appeared first on Microsoft Security Blog. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":58421,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[5449,244,10798],"class_list":["post-58420","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-credential-theft","tag-remote-code-execution","tag-storm"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Threat actors leverage tax season to deploy tax-themed phishing campaigns 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Threat actors leverage tax season to deploy tax-themed phishing campaigns 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2025-04-03T16:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/04\/image.webp\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"16 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Threat actors leverage tax season to deploy tax-themed phishing campaigns\",\"datePublished\":\"2025-04-03T16:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\\\/\"},\"wordCount\":2930,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/04\\\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns.webp\",\"keywords\":[\"Credential Theft\",\"remote code execution\",\"Storm\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\\\/\",\"name\":\"Threat actors leverage tax season to deploy tax-themed phishing campaigns 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/04\\\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns.webp\",\"datePublished\":\"2025-04-03T16:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/04\\\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns.webp\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/04\\\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns.webp\",\"width\":979,\"height\":557},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Credential Theft\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/credential-theft\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Threat actors leverage tax season to deploy tax-themed phishing campaigns\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Threat actors leverage tax season to deploy tax-themed phishing campaigns 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\/","og_locale":"en_US","og_type":"article","og_title":"Threat actors leverage tax season to deploy tax-themed phishing campaigns 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2025-04-03T16:00:00+00:00","og_image":[{"url":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/04\/image.webp","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"16 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Threat actors leverage tax season to deploy tax-themed phishing campaigns","datePublished":"2025-04-03T16:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\/"},"wordCount":2930,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/04\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns.webp","keywords":["Credential Theft","remote code execution","Storm"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\/","url":"https:\/\/www.threatshub.org\/blog\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\/","name":"Threat actors leverage tax season to deploy tax-themed phishing campaigns 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/04\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns.webp","datePublished":"2025-04-03T16:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/04\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns.webp","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/04\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns.webp","width":979,"height":557},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Credential Theft","item":"https:\/\/www.threatshub.org\/blog\/tag\/credential-theft\/"},{"@type":"ListItem","position":3,"name":"Threat actors leverage tax season to deploy tax-themed phishing campaigns"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/58420","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=58420"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/58420\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/58421"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=58420"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=58420"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=58420"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}