HomeSecurityA new Emotet phishing campaign targets taxpayers in the US

A new Emotet phishing campaign targets US taxpayers

A new Emotet phishing campaign is targeting U.S. taxpayers by impersonating W-9 tax forms allegedly sent by the Internal Revenue Service and the companies they work with.

The destructive Emotet malware spreads via phishing emails, which often contain malicious macros in Microsoft Word and Excel documents. If opened, the malware will be installed on your device.

However, after Microsoft began blocking macros by default in downloaded Office documents, Emotet switched to using Microsoft OneNote files with embedded scripts to install the Emotet malware.

Once Emotet is installed on someone's system, it will not only steal emails to use in replication attacks, but will also send additional spam emails and deploy other malware. This opens the door for hackers such as ransomware gangs seeking to infiltrate victims' computers and gain initial access.

Emotet
Emotet malware is distributed as fake W-9 tax forms from the IRS

Emotet is preparing for US tax season

In order to take advantage of the hustle and bustle of tax season in the US, Emotet malware operators often use themed phishing in conjunction with the holidays and other annual business activities.

Malwarebytes and Palo Alto Networks' Unit42 have observed a new phishing campaign in which the Emotet malware targets victims with emails containing fake W-9 tax return form attachments.

Malwarebytes recently identified a malicious campaign involving emails with the subject line “IRS Tax Forms W-9,” which were sent by a fraudster claiming to be an Internal Revenue Service inspector.

These malicious phishing emails are accompanied by a large ZIP file titled “W-9 form.zip”, which contains a dangerous Word, and to avoid detection by security software, the file size was intentionally increased to more than 500MB!

Emotet

Thanks to Microsoft's recent blocking of macros by default, users are much less likely to fall victim to malicious Word documents, as an extra effort is now required to enable macros.

A new Emotet phishing campaign targets US taxpayers

Brad Duncan from Unit42 observed a phishing attack where attackers bypassed security measures by using Microsoft OneNote documents containing embedded VBScript files that deploy the Emotet malware.

As shown in the image below, this phishing campaign uses chain response emails that pretend to be from business partners and contain W-9 forms.

A new Emotet phishing campaign targets US taxpayers

Don't be fooled by seemingly authentic OneNote documents that appear to require you to double-click the 'View' button to view properly. When clicked, these files will actually launch a VBScript document.

Emotet malware is distributed as fake W-9 tax forms from the IRS

When launching the embedded VBScript file, Microsoft OneNote will warn the user that the file may be malicious. Unfortunately, history has shown us that many users ignore these warnings and simply allow the files to run.

Once launched, the VBScript will download and then launch the Emotet DLL with regsvr32.exe for efficient execution.

Unbeknownst to the user, the malware now runs silently in the background, stealing emails and contacts, while waiting for more dangerous payloads to be installed on their device.

If you have been emailed W-9 forms or other tax forms, make sure to scan the documents with your local antivirus software first. However, given the confidential nature of these documents, it is recommended that you refrain from uploading them to scanning services such as VirusTotal.

Tax forms are generally delivered as PDFs, not Word attachments. If you receive such a form, it is a good idea to avoid opening the file and enabling macros.

Under no circumstances should you open a OneNote document claiming to be from the IRS - instead, delete that email immediately. Not only is it extremely unlikely that such tax forms as OneNote documents, but they could also contain malware.

As a precautionary measure, you should delete messages from unknown senders. Additionally, if you recognize the sender's name, confirm their identity with a phone call before opening any emails they send.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS