The IRS Impostor Blast That Hit 29,000 Inboxes Installed Signed ScreenConnect, and the Kits Did Not Retire After Tax Day

El malware que llegó disfrazado como un visor de transcripción IRS no necesitaba un virus personalizado. Necesitaba un programa de acceso remoto que ayudara a los escritorios a confiar, una firma de la empresa que la vende, y una bandeja de entrada perteneciente a alguien cuyo trabajo es abrir apegos fiscales. Esa combinación superó el 15 de abril.

El 19 de marzo de 2026, Microsoft Threat Intelligence y Microsoft Defender Security Research publicaron la anatomía de una temporada de equipos de seguridad ya habían estado observando. Correo con temática fiscal planteado como avisos de reembolso, formularios de nómina y alertas sobre Números de identificación de llenado electrónico. Algunos mensajes solo querían una contraseña. Others installed legitimate remote monitoring and management software. La mayor explosión, el 10 de febrero, alcanzó a más de 29.000 usuarios en más de 10.000 organizaciones. Alrededor del 95% de los objetivos estaban en los Estados Unidos. Dos olas corrieron entre las 10:35 y las 19:51 UTC. Bancos, empresas tecnológicas y minoristas absorbieron grandes acciones del volumen, pero los lectores previstos se agruparon alrededor de contadores y preparadores de impuestos. La escritura está en Microsoft Security Blog.
The AEGIS Alliance está menos interesado en el traje de temporada que en la herramienta debajo de ella. Una mirada binaria de ScreenConnect firmada, a un firewall cansado, como un técnico haciendo un trabajo. Es por eso que los mismos kits seguían siendo útiles en julio, agosto y septiembre, mucho después de que el último formulario de extensión dejara un escritorio.
The Transcript Viewer Was ConnectWise in a Costume
The February messages claimed irregular returns had been filed under the recipient’s EFIN and offered a button labeled «Download IRS Transcript View 5.1.» Amazon SES sent the mail. The button led to smartvault[.]im, a look-alike of the real SmartVault document platform, sitting behind Cloudflare checks meant to keep automated scanners out. After a fake verification animation, the victim received TranscriptViewer5.1.exe. It was a repackaged ScreenConnect build signed by ConnectWise. Once it ran, an operator had a remote session, a path to credentials, and a beachhead for whatever came next. No ransom note. No splash screen. Just a help-desk tool pointed the wrong direction.
El Hacker News hizo explícito el objetivo. Esto no era un spray en hogares al azar. Estaba dirigido a personas cuyo día de trabajo es una pila de apegos fiscales. Ese es un problema diferente a un código QR de reembolso enviado a una cuenta personal de Gmail, aunque ambos aparecieron en la misma temporada. Los productos de punta final que cazan basura desconocida se burlarán de un vendedor que ya lo permite. Un preparador que cree que el IRS acaba de entregar un visor hará clic. El resto del compromiso es silencioso.
When One Brand Got Hot, the Kits Changed Brands
Follow-on waves on February 23 and 27 used the subject line «IR-2026-216,» Eventbrite-styled IRS branding, and a «Cryptocurrency Tax Form 1099» lure aimed at higher education. Domains such as irs-doc[.]com and gov-irs216[.]net dropped IRS-doc.msi files that installed ScreenConnect or SimpleHelp. Variants aimed at accounting firms installed Datto. Microsoft’s researchers noted the same industry trend Huntress had quantified: remote-management abuse up sharply year over year, sometimes daisy-chained so that no single vendor’s telemetry tells the whole story. Elastic Security Labs researchers Daniel Stepanic and Salim Bitam put the design in one sentence. These tools are already trusted inside corporate networks, so they do not trip the alarms reserved for unknown binaries.
El robo credencial corrió junto a los instaladores. Un kit rastreado como Energy365, estimado para empujar cientos de miles de mensajes al día, usó marca CPA. SneakyLog, también rastreado como Kratos, escondió códigos QR en archivos adjuntos personalizados W-2 que abrió entradas falsas de Microsoft 365 y captó códigos multifactoriales. El IRS Dirty Dozen para 2026 volvió a enumerar la impersonación por correo electrónico y texto en la parte superior y repitió la única regla que se ha mantenido fiel: la agencia no comienza el contacto por correo electrónico, texto o redes sociales no solicitados para exigir datos o pago. Ese recordatorio sigue vivo IRS.gov. It has lived there for years. The inboxes still open.
Item eleven on that Dirty Dozen list is the quiet one. It describes «new client» and «document request» mail that delivers malware and steals client files. The February 10 blast was that item at industrial scale. The agency also reported more than 600 social-media impersonators during fiscal 2025. None of those accounts needed a ScreenConnect binary. They needed a logo and a deadline.
The July Chain Did Not Even Need the IRS Logo
By summer the costume had loosened. A July incident advisory circulated by CyberHoot, tagged CH-TA-2026-0001, described a preparer who was approached as a prospective client named «Teresa Bair.» The first contact came through the firm’s own website form. Rapport lasted weeks. A «tax meeting» produced a Microsoft Teams link whose visible text read teams.microsoft.com while the real address enrolled the workstation into an attacker-controlled Rippling device-management tenant. Scripts then ran as SYSTEM and tried to plant a second ScreenConnect instance plus FleetDeck, a backup remote tool, so that killing one brand would leave the other. That is the daisy chain in practice, not in a slide.
Agosto trajo un envoltorio diferente y la misma carga útil. El equipo de OpsCTI de LevelBlue, escribiendo el 7 de agosto, describió una gran carrera de phishing que impersonó el Microsoft Store y el Apple App Store. diálogos de actualización falsos para Google Meet, Adobe Acrobat, equipos, Zoom, DocuSign y otras herramientas de trabajo ordinarias ofrecieron un cliente de conexión de pantalla no autorizado. sin formulario de impuestos. No hay efin. Solo una caja que parecía un software que el usuario ya quería instalar. El 4 de septiembre, el investigador de seguridad Vladimir Khoetsyan describió una cadena relacionada en público: un señuelo de impuestos, una cremallera encriptada, un script Visual Basic, PowerShell y un instalador firmado Para Screenconnect o GoTo Resolve. Dijo que el 94 por ciento de alrededor de 240 anfitriones en ese conjunto vivieron sólo un día, por lo que los bloqueistas pierden. La instalación es la señal. Un agente de acceso remoto que nadie ordenó en IT es el incidente.
Una sesión informativa del 10 de septiembre de la firma de hospedaje Verito todavía utilizó la campaña de revisión de transcripciones de febrero como los preparadores de ejemplo deben memorizar: 14 nombres de remitente rotativos, una falsa EFIN revisión, un aspecto SmartVault, una herramienta remota firmada. El calendario se había mudado. La plantilla no tenía. Los pagos trimestrales estimados en septiembre y enero mantienen la misma ansiedad en los mismos buzones de correo. Un socio que hizo caso omiso de un visor de transcripción en febrero todavía abrirá un aviso de falta de pago en el otoño. Los atacantes alquilan infraestructura de nuevo. Ellos cambian la línea de asunto. Las estancias binarias firmadas porque la confianza permanece.
A Tax Mailbox Is Worth More Than One Refund
Los preparadores tienen números de Seguro Social, números de enrutamiento bancario y rendimientos de años anteriores para listas completas de clientes. Un buzón de transferencia de fondos de reembolso fraude y el tipo de robo de identidad aguas abajo documentado en el 700Credit breach that exposed nearly 6 million car buyers. Microsoft’s researchers noted that the professionals in the blast were «accustomed to receiving tax-related emails during this period,» which is exactly why the lures work. CISA, the NSA, and MS-ISAC have already warned that portable remote-management executables can run as a local user without a full install, a path used against federal civilian networks. A firm that banned ScreenConnect in February and never looked for SimpleHelp, Datto, FleetDeck, or GoTo Resolve in May did not close the campaign. It changed the costume.
The same habit shows up across The AEGIS Alliance cyber file: borrow something people already trust, then empty what it can reach. That is the shape of the Phantom Hacker bank-drain warning, el Treasury remote-access incident, y shadow network Google said had been riding ordinary phones. Different brands. Same idea.
What Actually Shrinks the Next Wave
Multifactor authentication on mail and financial accounts, conditional access that blocks odd sign-ins, and a written ban on installing any remote-access tool IT did not request are the minimum. Staff should open IRS accounts by typing the official address, never by clicking a button in a message. Suspicious mail can go to ph******@*rs.gov. Endpoint tools need to flag the first time ScreenConnect, SimpleHelp, Datto, FleetDeck, LogMeIn, or GoTo Resolve appears on a machine, not just unsigned junk.
Accounting shops should treat a surprise «transcript viewer» the way a bank treats a surprise wire. Call the person who is supposed to have sent it, on a number already on file. Do not call the number in the email. Do not run the file «to see if it looks real.» A signed ConnectWise binary that nobody ordered is not a tool. It is a key. Cleanup that only uninstalls the brand named in a blog post is theater. Pull every unexpected remote-access service, rotate the credentials that lived on that box, and treat every token on the machine as burned. The AEGIS Alliance will keep following how impersonation campaigns migrate from a filing deadline to whatever deadline comes next, on the hacker news y U.S. news desks.
The IRS logo was wrapping. Trust was the product. Anyone still reading the danger as a problem that ended on Tax Day is watching the calendar instead of the installer.










Un comentario