A new targeted phishing has been spotted by security researchers targeting high-level security professionals at technology companies, such as CTOs.

Given that the deadline for filing tax returns in the US is approaching (the specified deadline is April 15), it is no surprise that cybercriminals have chosen this topic to lure victims into downloading malware.
Researchers at Talos, Cisco 's information security and research group , observed the development of the malicious campaign on Tuesday, which delivered emails with themes related to different payment details and federal taxes.
The messages contained a malicious attachment that appeared as a Word document with a macro (a script used to automate repetitive tasks) and carried instructions for users to download a malware dropper that funneled the Vawtrak Trojan.
According to researchers, both the messages and the malicious Word file are constantly updated as different versions were recorded on Wednesday.
In the first wave of the attack, the sender address was spoofed to appear as support@gov.com or support@link2.gov, stating that the tax payment was accepted. The newer version contained different sender addresses and stated that the tax information was not received.
The message also included details about a large sum of money, likely in an attempt to incentivize the recipient to open the malicious document. Both samples stated that a receipt would be available by printing the attached file.
Depending on a company's field of activity, technology professionals, Chief Technology Officers (CTOs) in particular, are well aware of the risks and it comes as no surprise that they were targeted in the current phishing campaign.
Researchers analyzed the version of Vawtrak distributed this way and determined that it has the ability to record user credentials for more than 100 online services, most of which belong to financial institutions. However, “the list does not include some mobile phone providers and other online retail websites.”
There has been an increase in the distribution of Vawtrak recently. Security researchers at Trend Micro recently discovered a different phishing campaign that distributes this malware via macros in Word documents.
