Microsoft warns about tax-related fraud campaigns
Microsoft Threat Intelligence's tax season report highlights some of the various tactics, techniques and procedures that financially motivated threat actors use to craft their campaigns and mislead taxpayers into revealing sensitive information, making payments to fake services, or installing malicious payloads.
Microsoft security researchers identified a campaign using lures masquerading as tax-related documents provided by employers towards the end of January 2024. The phishing email contained an HTML attachment directing the user to a fake landing page which hosted malicious executables. Once the user clicked on the " Download Documents" prompt, it triggered the download of malware onto the user's computer.
Upon infiltration, the malicious executable file systematically sought out and extracted sensitive data, including login credentials, from the compromised system.
"Phishing email campaigns around tax season use a variety of tactics to trick users into believing they represent legitimate sources. These include spoofing the landing pages of genuine services or websites, using homoglyph domains, and customizing phishing links for each user. Threat actors typically impersonate employers and human resources personnel, the Internal Revenue Service (IRS), or taxation-related entities such as state tax organizations or tax preparation services," Microsoft wrote in a blog post.
Microsoft has shared the following tips to protect yourself from tax-related fraud campaigns:
- Inspect the sender's email address to verify that everything is in order - misplaced characters or unusual spellings could indicate a fraudulent attempt.
- Be wary of emails with generic greetings like "Dear customer" that ask you to act urgently.
- Before responding to any requests for information, verify the sender's contact details. If you have any doubts, it's safer to initiate a new email thread using known contact information rather than replying directly.
- Avoid sharing sensitive information by email. If you need to share sensitive information, go for a phone conversation.
- Think twice before clicking on unexpected links, especially those that prompt you to sign into an account.
- Opening email attachments from unknown sources or even from friends who do not normally send you attachments can be risky.
- Install a phishing filter for your email apps and enable the spam filter on your email accounts.
Google News