The IRS Impostor Blast That Hit 29,000 Inboxes Installed Signed ScreenConnect, and the Kits Did Not Retire After Tax Day

Le malware qui est arrivé déguisé en visionneur de transcription IRS n'avait pas besoin d'un virus personnalisé. Il avait besoin d'un programme d'accès à distance dont les bureaux d'aide faisaient déjà confiance, d'une signature de l'entreprise qui le vend et d'une boîte de réception appartenant à une personne dont le travail consiste à ouvrir des pièces jointes fiscales. Cette combinaison a survécu le 15 avril.

Le 19 mars 2026, Microsoft Threat Intelligence et Microsoft Defender Security Research ont publié l'anatomie d'une saison des équipes de sécurité avaient déjà regardé. Le courrier sur le thème de l'impôt se présente sous la forme d'avis de remboursement, de formulaires de paye et d'alertes concernant les numéros d'identification électronique pour la production. Certains messages voulaient seulement un mot de passe. D'autres ont installé un logiciel légitime de surveillance et de gestion à distance. L'explosion la plus importante, le 10 février, a touché plus de 29 000 utilisateurs dans plus de 10 000 organisations. Environ 95 % des cibles étaient aux États-Unis. Deux vagues ont couru entre 10h35 et 19h51 UTC. Les banques, les entreprises technologiques et les détaillants ont absorbé une grande partie du volume, mais les lecteurs visés se sont regroupés autour des comptables et des fiscalistes. L'écriture est sur le Microsoft Security Blog.
L'Alliance AEGIS est moins intéressé par le costume de saison que dans l'outil en dessous. Un binaire ScreenConnect signé ressemble à un pare-feu fatigué, comme un technicien faisant un travail. C'est pourquoi les mêmes kits ont été encore utiles en juillet, août et septembre, bien après que le dernier formulaire d'extension a laissé un bureau.
The Transcript Viewer Was ConnectWise in a Costume
The February messages claimed irregular returns had been filed under the recipient’s EFIN and offered a button labeled « Download IRS Transcript View 5.1. » Amazon SES sent the mail. The button led to smartvault[.]im, a look-alike of the real SmartVault document platform, sitting behind Cloudflare checks meant to keep automated scanners out. After a fake verification animation, the victim received TranscriptViewer5.1.exe. It was a repackaged ScreenConnect build signed by ConnectWise. Once it ran, an operator had a remote session, a path to credentials, and a beachhead for whatever came next. No ransom note. No splash screen. Just a help-desk tool pointed the wrong direction.
The Hacker News a rendu le ciblage explicite. Ce n'était pas une pulvérisation dans les ménages aléatoires. Il s'adressait aux personnes dont la journée de travail est un tas d'attachements fiscaux. C'est un problème différent d'un remboursement QR code envoyé à un compte personnel Gmail, bien que les deux sont arrivés dans la même saison. Les produits d'extrémité qui chassent les pourriels inconnus vont s'écraser chez un fournisseur IT permet déjà. Un préparateur qui pense que l'IRS vient de remettre un spectateur cliquera. Le reste du compromis est calme.
When One Brand Got Hot, the Kits Changed Brands
Follow-on waves on February 23 and 27 used the subject line « IR-2026-216, » Eventbrite-styled IRS branding, and a « Cryptocurrency Tax Form 1099 » lure aimed at higher education. Domains such as irs-doc[.]com and gov-irs216[.]net dropped IRS-doc.msi files that installed ScreenConnect or SimpleHelp. Variants aimed at accounting firms installed Datto. Microsoft’s researchers noted the same industry trend Huntress had quantified: remote-management abuse up sharply year over year, sometimes daisy-chained so that no single vendor’s telemetry tells the whole story. Elastic Security Labs researchers Daniel Stepanic and Salim Bitam put the design in one sentence. These tools are already trusted inside corporate networks, so they do not trip the alarms reserved for unknown binaries.
Le vol de justificatifs a couru à côté des installateurs. Un kit suivi sous le nom d'Energy365, estimé à pousser des centaines de milliers de messages par jour, portait la marque CPA. SneakyLog, également suivi comme Kratos, des codes QR cachés dans des pièces jointes personnalisées W-2 qui ont ouvert de fausses connexions Microsoft 365 et capturé des codes multifacteurs. L'IRS Dirty Dozen pour 2026 a répertorié l'imitation par email et texte en haut et répété la seule règle qui est restée vraie: l'agence ne commence pas à contacter par e-mail, texte ou médias sociaux non sollicités pour demander des données ou un paiement. Ce rappel continue IRS.gov. It has lived there for years. The inboxes still open.
Item eleven on that Dirty Dozen list is the quiet one. It describes « new client » and « document request » mail that delivers malware and steals client files. The February 10 blast was that item at industrial scale. The agency also reported more than 600 social-media impersonators during fiscal 2025. None of those accounts needed a ScreenConnect binary. They needed a logo and a deadline.
The July Chain Did Not Even Need the IRS Logo
By summer the costume had loosened. A July incident advisory circulated by CyberHoot, tagged CH-TA-2026-0001, described a preparer who was approached as a prospective client named « Teresa Bair. » The first contact came through the firm’s own website form. Rapport lasted weeks. A « tax meeting » produced a Microsoft Teams link whose visible text read teams.microsoft.com while the real address enrolled the workstation into an attacker-controlled Rippling device-management tenant. Scripts then ran as SYSTEM and tried to plant a second ScreenConnect instance plus FleetDeck, a backup remote tool, so that killing one brand would leave the other. That is the daisy chain in practice, not in a slide.
August brought a different wrapper and the same payload. LevelBlue’s OpsCTI team, writing on August 7, described a large phishing run that impersonated the Microsoft Store and the Apple App Store. Fake update dialogs for Google Meet, Adobe Acrobat, Teams, Zoom, DocuSign, and other ordinary work tools offered an unauthorized ScreenConnect client. No tax form. No EFIN. Just a box that looked like software the user already meant to install. On September 4, security researcher Vladimir Khoetsyan described a related chain in public: a tax lure, an encrypted zip, a Visual Basic script, PowerShell, and a signed installer for ScreenConnect or GoTo Resolve. He said 94 percent of about 240 hosts in that set lived only a day, which is why blocklists lose. The install is the signal. A remote-access agent nobody in IT ordered is the incident.
A September 10 briefing from the hosting firm Verito still used the February transcript-viewer campaign as the example preparers should memorize: 14 rotating sender names, a fake EFIN review, a SmartVault look-alike, a signed remote tool. The calendar had moved. The template had not. Quarterly estimated payments in September and January keep the same anxiety in the same mailboxes. A partner who ignored a transcript viewer in February will still open a notice of underpayment in the fall. Attackers rent sending infrastructure again. They change the subject line. The signed binary stays because the trust stays.
A Tax Mailbox Is Worth More Than One Refund
Preparers hold Social Security numbers, bank routing numbers, and prior-year returns for entire client lists. One mailbox takeover funds refund fraud and the kind of downstream identity theft documented in the 700Credit breach that exposed nearly 6 million car buyers. Microsoft’s researchers noted that the professionals in the blast were « accustomed to receiving tax-related emails during this period, » which is exactly why the lures work. CISA, the NSA, and MS-ISAC have already warned that portable remote-management executables can run as a local user without a full install, a path used against federal civilian networks. A firm that banned ScreenConnect in February and never looked for SimpleHelp, Datto, FleetDeck, or GoTo Resolve in May did not close the campaign. It changed the costume.
The same habit shows up across The AEGIS Alliance cyber file: borrow something people already trust, then empty what it can reach. That is the shape of the Phantom Hacker bank-drain warning, les Treasury remote-access incidentet les shadow network Google said had been riding ordinary phones. Different brands. Same idea.
What Actually Shrinks the Next Wave
Multifactor authentication on mail and financial accounts, conditional access that blocks odd sign-ins, and a written ban on installing any remote-access tool IT did not request are the minimum. Staff should open IRS accounts by typing the official address, never by clicking a button in a message. Suspicious mail can go to ph******@*rs.gov. Endpoint tools need to flag the first time ScreenConnect, SimpleHelp, Datto, FleetDeck, LogMeIn, or GoTo Resolve appears on a machine, not just unsigned junk.
Accounting shops should treat a surprise « transcript viewer » the way a bank treats a surprise wire. Call the person who is supposed to have sent it, on a number already on file. Do not call the number in the email. Do not run the file « to see if it looks real. » A signed ConnectWise binary that nobody ordered is not a tool. It is a key. Cleanup that only uninstalls the brand named in a blog post is theater. Pull every unexpected remote-access service, rotate the credentials that lived on that box, and treat every token on the machine as burned. The AEGIS Alliance will keep following how impersonation campaigns migrate from a filing deadline to whatever deadline comes next, on the hacker news et U.S. news desks.
The IRS logo was wrapping. Trust was the product. Anyone still reading the danger as a problem that ended on Tax Day is watching the calendar instead of the installer.










Un commentaire