Jump to content
  • Microsoft warns accounting and tax return firms of a new phishing attack ahead of US Tax Day

    aum

    • 319 views
    • 2 minutes
     Share


    • 319 views
    • 2 minutes

    Benjamin Franklin once wrote, "The only two certainties in life are death and taxes". With the annual US Tax Day approaching on Tuesday, April 18, we might include a third certainty to that list: internet scams. This week, Microsoft's security division put out an alert on a new phishing scam that's targeting accounting and tax return firms ahead of Tax Day.

     

    Microsoft's blog post says that the company noticed the new scams in February. They are being sent out by hackers who hope they can deliver the Remcos remote access trojan to a PC. Remcos is designed to enter Windows PCs and take over administrator privileges remotely. Microsoft says:

     

    While social engineering lures like this one are common around Tax Day and other big topic current events, these campaigns are specific and targeted in a way that is uncommon. The targets for this threat are exclusively organizations that deal with tax preparation, financial services, CPA and accounting firms, and professional service firms dealing in bookkeeping and tax.

     

    1681474394_remcos-malware-phishing-lure-

     

    Naturally, these types of firms get very busy this time of year ahead of Tax Day with clients emailing them information about their taxes and financial information. Microsoft says that this phishing campaign has sent out emails that look like they come from a client of an accounting or tax firm. They contain a link to a real file-sharing service, with a real Amazon Web Services click-tracking link.

     

    Unfortunately for the person who clicks on that link, they will then be taken to the file-sharing site, where the hacker has placed Windows shortcut (.LNK) files. Microsoft says:

     

    These LNK files generate web requests to actor-controlled domains and/or IP addresses to download malicious files. These malicious files then perform actions on the target device and download the Remcos payload, providing the actor potential access to the target device and network.

     

    The good news for Windows PC users who work in those financial firms is that Microsoft 365 Defender and Microsoft Defender Antivirus can detect these malicious files and prevent the remote takeover of their PCs. Obviously, those users should always be suspicious of any emails that have links to file-sharing sites, especially from clients that they don't know.

     

    Source

    • Like 2

    User Feedback

    Recommended Comments

    There are no comments to display.



    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...