A new phishing campaign is targeting Greek taxpayers using phishing sites that mimic the state's official tax refund platform and steal banking details while typing (keylogger).

The goal of the scammers is to get victims to enter their banking credentials on phishing sites, to confirm that they are supposedly them and to authorize a tax refund.
However, whatever the user on these sites, even if they never click submit to complete the login process, is sent directly to the attackers.
See also: Why is vulnerability management proving so difficult?
The campaign was discovered by researchers at the company Cyble.
Phishing campaign targets Greek taxpayers
Fraudsters are sending phishing emails claiming that the tax office has calculated a tax refund of 634 euros but has failed to send the money to the beneficiary's bank account due to validation problems.

The emails contain links that point to multiple phishing URLs that impersonate the Greek government's tax portal, such as “govgr-tax[.]me/ret/tax”, “govgreece-tax[.]me” and “mygov-refund[. ]me/ret/tax”.
On the fake portal, visitors are asked to select the banking institution they are working with. The attackers offer seven options, including several major Greek banks.

Depending on the selection, the user is redirected to a fake login page themed after the selected financial institution, hosted on the same phishing domain.
See also: Hackers have injected malware into extensions from FishPig
These pages contain a JavaScript keylogger that records all keystrokes of Greek users and sends them to the attackers' server. This way, the fraudsters have access to stolen banking credentials in real time.
The problem is that even if the victim realizes the fraud before completing the login to their bank account, the attackers will have already stolen the credentials thanks to the keylogger.
The use of real-time keylogging, as seen in this phishing campaign targeting Greek taxpayers, is rare and could be the beginning of a new trend in phishing attacks.
Using a keylogger increases the success rate of the attack.
The JavaScript keylogger will load and operate as intended, even if the victim has set their browser to block all third-party trackers, so there is no way to proactively stop it.
See also: WPGateway: Serious zero-day bug found in WordPress plugin
This new phishing campaign is very dangerous. Therefore, you should be extra careful when receiving messages and emails offering money, items, and other benefits.
In cases like the above, use a search engine to locate the official tax portal (or other service) of your country and only log in from there if necessary. Only on the official page can you see with more certainty whether you actually have a tax refund, etc.

As always, do not click on links embedded in emails or contained in attached files such as DOCX and PDF without first confirming their authenticity.
Also, to stay generally safe, enable automatic software updates on your computer, mobile phone, and other connected devices , and use a reliable antivirus program.
Finally, regularly monitor your financial transactions and if you notice any suspicious activity, contact your bank immediately.
Source: www.bleepingcomputer.com
