Hacker NewsNachrichtenWeitere VideosVereinigte Staaten NewsVideos

The IRS Impostor Blast That Hit 29,000 Inboxes Installed Signed ScreenConnect, and the Kits Did Not Retire After Tax Day

IRS releases ‘Dirty Dozen' tax scams for 2026 season

Die Malware, die als IRS-Transkript-Viewer getarnt ankam, benötigte keinen benutzerdefinierten Virus. Es brauchte ein Fernzugriffsprogramm, dem die Schreibtische bereits vertrauen, eine Unterschrift des Unternehmens, das es verkauft, und einen Posteingang von jemandem, dessen Aufgabe es ist, Steueranhänge zu öffnen. Diese Kombination überlebte den 15. April.

Example of the 2026 IRS impostor phishing lure reported by The AEGIS Alliance after Microsoft's tax-season warning
An example of what the 2026 IRS phishing scam looks like.

Am 19. März 2026 veröffentlichten Microsoft Threat Intelligence und Microsoft Defender Security Research die Anatomie einer Saison, die Sicherheitsteams bereits beobachtet hatten. Steuerliche Post, die als Rückerstattungsbescheide, Lohnabrechnungsformulare und Benachrichtigungen über elektronische Einreichungsidentifikationsnummern ausgegeben wird. Einige Nachrichten wollten nur ein Passwort. Andere installierten legitime Fernüberwachungs- und Verwaltungssoftware. Die größte Explosion am 10. Februar erreichte mehr als 29.000 Benutzer in über 10.000 Organisationen. Etwa 95 Prozent der Ziele lagen in den USA. Zwei Wellen liefen zwischen 10:35 und 19:51 UTC. Banken, Technologieunternehmen und Einzelhändler absorbierten große Anteile des Volumens, aber die beabsichtigten Leser gruppierten sich um Buchhalter und Steuerberater. Der Write-up ist auf dem Microsoft Security Blog.

Die AEGIS-Allianz interessiert sich weniger für das saisonale Kostüm als für das Werkzeug darunter. Eine signierte ScreenConnect-Binärdatei sieht für eine müde Firewall aus wie ein Techniker, der einen Job macht. Deshalb waren die gleichen Kits noch im Juli, August und September nützlich, lange nachdem das letzte Erweiterungsformular einen Schreibtisch verlassen hatte.

The Transcript Viewer Was ConnectWise in a Costume

The February messages claimed irregular returns had been filed under the recipient’s EFIN and offered a button labeled „Download IRS Transcript View 5.1.“ Amazon SES sent the mail. The button led to smartvault[.]im, a look-alike of the real SmartVault document platform, sitting behind Cloudflare checks meant to keep automated scanners out. After a fake verification animation, the victim received TranscriptViewer5.1.exe. It was a repackaged ScreenConnect build signed by ConnectWise. Once it ran, an operator had a remote session, a path to credentials, and a beachhead for whatever came next. No ransom note. No splash screen. Just a help-desk tool pointed the wrong direction.

The Hacker News das Targeting explizit gemacht. Dies war kein Spray in zufälligen Haushalten. Es richtete sich an Menschen, deren Arbeitstag ein Haufen Steueranhänge ist. Das ist ein anderes Problem als ein Rückerstattungs-QR-Code, der an ein persönliches Gmail-Konto gesendet wird, obwohl beide in der gleichen Saison auftauchten. Endpunktprodukte, die nach unbekanntem Müll suchen, zucken einen Anbieter, den die IT bereits zulässt. Ein Vorbereiter, der denkt, dass der IRS gerade einen Zuschauer übergeben hat, wird klicken. Der Rest des Kompromisses ist ruhig.

When One Brand Got Hot, the Kits Changed Brands

Follow-on waves on February 23 and 27 used the subject line „IR-2026-216,“ Eventbrite-styled IRS branding, and a „Cryptocurrency Tax Form 1099“ lure aimed at higher education. Domains such as irs-doc[.]com and gov-irs216[.]net dropped IRS-doc.msi files that installed ScreenConnect or SimpleHelp. Variants aimed at accounting firms installed Datto. Microsoft’s researchers noted the same industry trend Huntress had quantified: remote-management abuse up sharply year over year, sometimes daisy-chained so that no single vendor’s telemetry tells the whole story. Elastic Security Labs researchers Daniel Stepanic and Salim Bitam put the design in one sentence. These tools are already trusted inside corporate networks, so they do not trip the alarms reserved for unknown binaries.

Credential Diebstahl lief neben den Installateuren. Ein Kit, das als Energy365 verfolgt wurde und schätzungsweise Hunderttausende von Nachrichten pro Tag verbreitet, trug CPA-Branding. SneakyLog, auch als Kratos verfolgt, versteckte QR-Codes in personalisierten W-2-Anhängen, die gefälschte Microsoft 365-Logins öffneten und Multifaktor-Codes erfassten. Das IRS Dirty Dozen für 2026 listete erneut die Imitation per E-Mail und Text oben auf und wiederholte die einzige Regel, die wahr geblieben ist: Die Agentur beginnt keinen Kontakt mit unaufgeforderte e-mails, texte oder soziale medien, um daten oder zahlungen zu verlangen. Diese Erinnerung lebt IRS.gov. It has lived there for years. The inboxes still open.

Item eleven on that Dirty Dozen list is the quiet one. It describes „new client“ and „document request“ mail that delivers malware and steals client files. The February 10 blast was that item at industrial scale. The agency also reported more than 600 social-media impersonators during fiscal 2025. None of those accounts needed a ScreenConnect binary. They needed a logo and a deadline.

The July Chain Did Not Even Need the IRS Logo

By summer the costume had loosened. A July incident advisory circulated by CyberHoot, tagged CH-TA-2026-0001, described a preparer who was approached as a prospective client named „Teresa Bair.“ The first contact came through the firm’s own website form. Rapport lasted weeks. A „tax meeting“ produced a Microsoft Teams link whose visible text read teams.microsoft.com while the real address enrolled the workstation into an attacker-controlled Rippling device-management tenant. Scripts then ran as SYSTEM and tried to plant a second ScreenConnect instance plus FleetDeck, a backup remote tool, so that killing one brand would leave the other. That is the daisy chain in practice, not in a slide.

August brachte einen anderen Wrapper und die gleiche Nutzlast. Das OpsCTI-Team von LevelBlue beschrieb am 7. August einen großen Phishing-Lauf, der den Microsoft Store und den Apple App Store verkörperte. Gefälschte update-dialoge für Google Meet, Adobe Acrobat, Teams, Zoom, DocuSign und andere normale arbeitswerkzeuge boten einen nicht autorisierten screenconnect-client an. kein Steuerformular. keine Efin. Nur eine Box, die wie Software aussah, die der Benutzer bereits installieren wollte. Am 4. September beschrieb der Sicherheitsforscher Vladimir Khoetsyan eine verwandte Kette in der Öffentlichkeit: eine Steuerköderung, eine verschlüsselte Zip, ein Visual Basic Skript, PowerShell und ein signiertes Installationsprogramm Für screenconnect oder GoTo Resolve. Er sagte, 94 Prozent von etwa 240 Hosts in diesem Set lebten nur einen Tag, weshalb Blocklisten verlieren. Die Installation ist das Signal. Ein Remote-Access-Agent, den niemand in der IT bestellt hat, ist der Vorfall.

Ein Briefing vom 10. September von der Hosting-Firma Verito nutzte immer noch die Transkript-Viewer-Kampagne vom Februar, da sich die Beispielgeber merken sollten: 14 rotierende Absendernamen, eine Fälschung EFIN-Bewertung, ein SmartVault-Look-alike, ein signiertes Remote-Tool. Der Kalender war umgezogen. Das Template hatte es nicht. Vierteljährlich geschätzte Zahlungen im September und Januar halten die gleiche Angst in den gleichen Postfächern. Ein Partner, der einen Transkript-Viewer im Februar ignorierte, wird im Herbst immer noch eine Mitteilung über Unterzahlung öffnen. Angreifer mieten erneut Sendeinfrastruktur. Sie ändern die Betreffzeile. Die signierte Binärdatei bleibt, weil das Vertrauen bleibt.

A Tax Mailbox Is Worth More Than One Refund

Bereitsteller halten Sozialversicherungsnummern, Bankleitzahlen und Vorjahresrenditen für ganze Kundenlisten. Ein Postfach-Übernahmefonds erstattet Betrug und die Art des nachgelagerten Identitätsdiebstahls, der im 700Credit breach that exposed nearly 6 million car buyers. Microsoft’s researchers noted that the professionals in the blast were „accustomed to receiving tax-related emails during this period,“ which is exactly why the lures work. CISA, the NSA, and MS-ISAC have already warned that portable remote-management executables can run as a local user without a full install, a path used against federal civilian networks. A firm that banned ScreenConnect in February and never looked for SimpleHelp, Datto, FleetDeck, or GoTo Resolve in May did not close the campaign. It changed the costume.

The same habit shows up across The AEGIS Alliance cyber file: borrow something people already trust, then empty what it can reach. That is the shape of the Phantom Hacker bank-drain warning, Treasury Remote Access Vorfall, und die shadow network Google said had been riding ordinary phones. Different brands. Same idea.

What Actually Shrinks the Next Wave

Multifactor authentication on mail and financial accounts, conditional access that blocks odd sign-ins, and a written ban on installing any remote-access tool IT did not request are the minimum. Staff should open IRS accounts by typing the official address, never by clicking a button in a message. Suspicious mail can go to ph******@*rs.gov. Endpoint tools need to flag the first time ScreenConnect, SimpleHelp, Datto, FleetDeck, LogMeIn, or GoTo Resolve appears on a machine, not just unsigned junk.

Accounting shops should treat a surprise „transcript viewer“ the way a bank treats a surprise wire. Call the person who is supposed to have sent it, on a number already on file. Do not call the number in the email. Do not run the file „to see if it looks real.“ A signed ConnectWise binary that nobody ordered is not a tool. It is a key. Cleanup that only uninstalls the brand named in a blog post is theater. Pull every unexpected remote-access service, rotate the credentials that lived on that box, and treat every token on the machine as burned. The AEGIS Alliance will keep following how impersonation campaigns migrate from a filing deadline to whatever deadline comes next, on the hacker news und Vereinigte Staaten News schreibtische.

The IRS logo was wrapping. Trust was the product. Anyone still reading the danger as a problem that ended on Tax Day is watching the calendar instead of the installer.

Kyle James Lee
Mehrheitseigentümer der AEGIS Alliance. Ich habe am College für Medienkunst, Spieleentwicklung studiert. Zu den Talenten gehören Autor / Artikelautor, Grafikdesign, Photoshop, Webdesign und -entwicklung, Videoproduktion, Social Media und E-Commerce.

Ähnliche Artikel

Ein Kommentar

  1. Pingback: URL

Schreibe einen Kommentar

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

Schaltfläche "Zurück zum Anfang"