{"id":1186701,"date":"2026-03-23T04:49:53","date_gmt":"2026-03-23T11:49:53","guid":{"rendered":"https:\/\/theaegisalliance.com\/?p=1186701"},"modified":"2026-09-03T12:42:54","modified_gmt":"2026-09-03T19:42:54","slug":"irs-impostors-phishing-scam-surge-microsoft-warns-29000-users-targeted-with-rmm-malware","status":"publish","type":"post","link":"https:\/\/theaegisalliance.com\/fr\/2026\/03\/23\/une-vague-descroqueries-par-hameconnage-se-faisant-passer-pour-le-fisc-americain-irs-deferle-microsoft-met-en-garde-contre-29-000-utilisateurs-cibles-par-un-logiciel-malveillant-rmm\/","title":{"rendered":"IRS Impostor Mail Hit 29,000 Inboxes With Signed ScreenConnect and the Same Kits Are Still Useful After Tax Day"},"content":{"rendered":"<div class=\"epyt-video-wrapper\">\n<div  style=\"display: block; margin: 0px auto;\"  id=\"_ytid_46444\"  width=\"480\" height=\"270\"  data-origwidth=\"480\" data-origheight=\"270\" data-facadesrc=\"https:\/\/www.youtube.com\/embed\/Juv8B56rm08?enablejsapi=1&#038;origin=https:\/\/theaegisalliance.com&#038;autoplay=0&#038;cc_load_policy=0&#038;cc_lang_pref=&#038;iv_load_policy=1&#038;loop=0&#038;rel=0&#038;fs=1&#038;playsinline=0&#038;autohide=2&#038;theme=dark&#038;color=red&#038;controls=1&#038;disablekb=0&#038;\" class=\"__youtube_prefs__ epyt-facade epyt-is-override  no-lazyload\" data-epautoplay=\"1\" ><img decoding=\"async\" data-spai-excluded=\"true\" class=\"epyt-facade-poster skip-lazy\" loading=\"lazy\"  alt=\"IRS releases \u2018Dirty Dozen&#039; tax scams for 2026 season\"  src=\"https:\/\/i.ytimg.com\/vi\/Juv8B56rm08\/maxresdefault.jpg\"  \/><button class=\"epyt-facade-play\" aria-label=\"Play\"><svg data-no-lazy=\"1\" height=\"100%\" version=\"1.1\" viewBox=\"0 0 68 48\" width=\"100%\"><path class=\"ytp-large-play-button-bg\" d=\"M66.52,7.74c-0.78-2.93-2.49-5.41-5.42-6.19C55.79,.13,34,0,34,0S12.21,.13,6.9,1.55 C3.97,2.33,2.27,4.81,1.48,7.74C0.06,13.05,0,24,0,24s0.06,10.95,1.48,16.26c0.78,2.93,2.49,5.41,5.42,6.19 C12.21,47.87,34,48,34,48s21.79-0.13,27.1-1.55c2.93-0.78,4.64-3.26,5.42-6.19C67.94,34.95,68,24,68,24S67.94,13.05,66.52,7.74z\" fill=\"#f00\"><\/path><path d=\"M 45,24 27,14 27,34\" fill=\"#fff\"><\/path><\/svg><\/button><\/div>\n<\/div>\n<p><em><strong>The April 15 filing deadline is behind us. The malware that rode in on fake IRS mail is not.<\/strong><\/em><\/p>\n<figure id=\"attachment_1186704\" aria-describedby=\"caption-attachment-1186704\" style=\"width: 1200px\" class=\"wp-caption alignnone\"><img decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-1186704\" src=\"https:\/\/theaegisalliance.com\/wp-content\/uploads\/IRS-Impostors-Phishing-Scam-Surge-Microsoft-Warns-29000-Users-Infected-with-RMM-Malware-2.jpg\" alt=\"Example of the 2026 IRS impostor phishing lure reported by The AEGIS Alliance after Microsoft's tax-season warning\" width=\"1200\" height=\"630\" \/><figcaption id=\"caption-attachment-1186704\" class=\"wp-caption-text\">An example of what the 2026 IRS phishing scam looks like.<\/figcaption><\/figure>\n<p>On March 19, 2026, Microsoft Threat Intelligence and Microsoft Defender Security Research published the campaign anatomy that security teams had already been seeing in their queues: tax-season mail dressed as refund notices, payroll forms, and EFIN alerts, split between credential-harvesting sites and payloads that install legitimate remote monitoring and management software. The flagship blast on February 10 reached more than 29,000 users at over 10,000 organizations. About 95 percent of the targets were in the United States. Two waves ran between 10:35 and 19:51 UTC. Financial services, technology, and retail absorbed the largest shares, but the intended inboxes clustered around accountants and tax preparers. The write-up lives on the <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/03\/19\/when-tax-season-becomes-cyberattack-season-phishing-and-malware-campaigns-using-tax-related-lures\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Microsoft Security Blog<\/a>.<\/p>\n<p><a href=\"https:\/\/theaegisalliance.com\/\">The AEGIS Alliance<\/a> is less interested in the calendar trick than in the payload choice. Attackers did not need a custom implant. They used software help desks already trust. That is why the same kits still matter in September, long after the last extension form left a desk.<\/p>\n<h2>The IRS Transcript Viewer Was ConnectWise With a Costume<\/h2>\n<p>Messages claimed irregular returns had been filed under the recipient&rsquo;s Electronic Filing Identification Number and pointed to a \u00ab\u00a0Download IRS Transcript View 5.1\u00a0\u00bb button. Amazon SES sent the mail. The button led to smartvault[.]im, a look-alike of the real SmartVault document platform, sitting behind Cloudflare checks meant to keep scanners out. After a fake verification animation, victims received TranscriptViewer5.1.exe \u2014 a repackaged ScreenConnect build signed by ConnectWise. Once launched, operators had remote control, credential access, and a beachhead for whatever came next.<\/p>\n<p>That is the design. A signed binary from a vendor that IT departments already allow through the door. Endpoint products that hunt for unknown junk will shrug. A user who thinks the IRS just handed them a viewer will click. The rest of the compromise is quiet. No ransom note. No splash screen. Just a remote session that looks, to a tired firewall, like a technician doing a job.<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/03\/microsoft-warns-irs-phishing-hits-29000.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">The Hacker News<\/a> summary of the same research made the targeting explicit: the blast was not a spray at random households. It was aimed at people whose job is to open tax attachments. That is a different problem than a grandma clicking a refund QR code, though both showed up in the same season.<\/p>\n<h2>When ScreenConnect Got Harder, the Kits Switched Brands<\/h2>\n<p>Follow-on waves on February 23 and 27 used subject line \u00ab\u00a0IR-2026-216,\u00a0\u00bb Eventbrite-styled IRS branding, and a \u00ab\u00a0Cryptocurrency Tax Form 1099\u00a0\u00bb lure aimed at higher education. Domains such as irs-doc[.]com and gov-irs216[.]net dropped IRS-doc.msi files that installed ScreenConnect or SimpleHelp. Accounting-firm variants installed Datto. Microsoft&rsquo;s researchers noted the same trend Huntress quantified industry-wide: RMM abuse up 277 percent year over year, sometimes daisy-chained so no single vendor&rsquo;s telemetry tells the whole story. Elastic Security Labs researchers Daniel Stepanic and Salim Bitam put the problem plainly \u2014 these tools are already trusted inside corporate networks, so they do not trip the alarms reserved for unknown binaries.<\/p>\n<p>Credential-theft kits ran in parallel. Energy365, estimated to push hundreds of thousands of messages a day, wore CPA branding. SneakyLog, also tracked as Kratos, hid QR codes in personalized W-2 attachments that opened fake Microsoft 365 logins and captured multifactor codes. The IRS Dirty Dozen for 2026 again listed impersonation by email and text at the top of the list and repeated the only reliable rule: the agency does not start contact by unsolicited email, text, or social media to demand data or payment. That reminder is on <a href=\"https:\/\/www.irs.gov\/newsroom\/dirty-dozen-tax-scams-for-2026-irs-reminds-taxpayers-to-watch-out-for-dangerous-threats\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">IRS.gov<\/a>. It has been on IRS.gov for years. The inboxes still open.<\/p>\n<p>The Dirty Dozen also flagged AI-enabled phone impersonation, social-media \u00ab\u00a0tax hacks,\u00a0\u00bb and spear-phishing aimed at tax professionals. Item eleven on that list is the quiet one. It describes \u00ab\u00a0new client\u00a0\u00bb and \u00ab\u00a0document request\u00a0\u00bb mail that delivers malware to steal client files. The February 10 blast was that item at industrial scale. The agency reported more than 600 social-media impersonators during fiscal 2025. None of those accounts needed a ScreenConnect binary. They needed a logo and a sense of urgency.<\/p>\n<h2>Why Tax Shops Remain the Prize After April<\/h2>\n<p>Preparers hold Social Security numbers, bank routing data, and prior-year returns for entire client lists. One mailbox takeover funds refund fraud and downstream identity theft of the kind documented in the <a href=\"https:\/\/theaegisalliance.com\/2025\/12\/17\/inside-the-700credit-breach-that-exposed-nearly-6-million-car-buyers\/\">700Credit breach that exposed nearly 6 million car buyers<\/a>. The professionals Microsoft described are \u00ab\u00a0accustomed to receiving tax-related emails during this period,\u00a0\u00bb which is exactly why the lures work. CISA, NSA, and MS-ISAC have already warned that portable RMM executables can run as a local user without a full install, a path used against federal civilian networks.<\/p>\n<p>The new problem is calendar-blind. Extension season, amended returns, and the next estimated-payment cycle keep the same inboxes hot. Signed RMM binaries will still look like IT doing its job. Organizations that only locked down during March and April are leaving the same door on the latch. A firm that banned ScreenConnect in February and never checked SimpleHelp or Datto in May has not closed the campaign. It has changed the costume.<\/p>\n<p>Quarterly estimated payments in September and January keep the same anxiety in the same mailboxes. A partner who ignored a fake transcript viewer in February will still open a fake \u00ab\u00a0notice of underpayment\u00a0\u00bb in the fall. Attackers know that. They rent Amazon SES again. They change the subject line. The signed binary stays the same because the trust stays the same.<\/p>\n<p>The same pattern showed up in other The AEGIS Alliance cyber files, including the <a href=\"https:\/\/theaegisalliance.com\/2024\/08\/25\/ngate-android-malware-steals-nfc-data-clones-no-contact-payment-cards\/\">NGate NFC cloning kit<\/a>, the <a href=\"https:\/\/theaegisalliance.com\/2025\/10\/31\/fbi-warns-of-new-phantom-hacker-scam-draining-bank-accounts-a-closer-look\/\">Phantom Hacker bank-drain warning<\/a>, and later reporting on how Chinese operators hit Treasury workstations in the <a href=\"https:\/\/theaegisalliance.com\/2024\/12\/30\/chinese-hackers-remotely-accessed-workstations-and-documents-in-a-major-cyber-incident-u-s-treasury-says\/\">Treasury remote-access incident<\/a>. Different brands. Same idea. Borrow trust, then empty the account.<\/p>\n<h2>What Actually Reduces the Chance of a Second Wave<\/h2>\n<p>Multifactor authentication on mail and financial accounts, conditional access that blocks odd sign-ins, and a written ban on installing any remote-access tool that IT did not request are the minimum. Staff should open IRS accounts by typing the official address, never by clicking a button in a message. Suspicious mail can go to <span \n                data-original-string='u6tN7sYtxYMAwq2oRFKAFw==9c6j8xO+oxG0SGUF9ouWjmxXWirIHYF8GbHaK8DLZhe9eI='\n                class='apbct-email-encoder'\n                title='This contact has been encoded by Anti-Spam by CleanTalk. Click to decode. To finish the decoding make sure that JavaScript is enabled in your browser.'>ph<span class=\"apbct-blur\">******<\/span>@<span class=\"apbct-blur\">*<\/span>rs.gov<\/span>. Endpoint tools need to flag first-seen ScreenConnect, SimpleHelp, Datto, and LogMeIn installs, not just unsigned junk.<\/p>\n<p>Accounting shops should treat a surprise \u00ab\u00a0transcript viewer\u00a0\u00bb the way a bank treats a surprise wire. Call the person who is supposed to have sent it on a number you already have. Do not call the number in the email. Do not run the exe to \u00ab\u00a0see if it looks real.\u00a0\u00bb A signed ConnectWise binary that nobody in IT ordered is not a tool. It is a key.<\/p>\n<p>Help desks should also assume daisy-chaining. Huntress has described attackers stacking one RMM inside another so that killing ScreenConnect leaves SimpleHelp running. A cleanup that only uninstalls the brand named in a blog post is theater. Pull the unexpected remote-access services, rotate credentials that lived on that box, and treat every token on that machine as burned. The AEGIS Alliance will keep tracking how impersonation campaigns migrate from seasonal lures to whatever deadline comes next, including the broader pattern in <a href=\"https:\/\/theaegisalliance.com\/category\/news\/hacker-news\/\">hacker news<\/a> and <a href=\"https:\/\/theaegisalliance.com\/category\/news\/us-news\/\">U.S. news<\/a>.<\/p>\n<p>Trust is the product. The IRS logo is just the wrapping. Anyone who still thinks the danger ended on April 15 is reading the calendar instead of the payload.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft logged more than 29,000 targets in a February 2026 IRS-themed blast that delivered signed ScreenConnect installers through a fake Transcript Viewer. The AEGIS Alliance looks at why remote-management tools IT departments already trust remain the attackers&rsquo; favorite after the April deadline passed.<\/p>\n","protected":false},"author":1,"featured_media":1186705,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[22,21,204522,24,204504],"tags":[192022,3674,233239,233186,52,213540],"class_list":["post-1186701","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacker-news","category-news","category-other-videos","category-us-news","category-videos","tag-hacker-news","tag-hackers","tag-irs","tag-microsoft","tag-news","tag-scam-alert"],"jetpack_featured_media_url":"https:\/\/theaegisalliance.com\/wp-content\/uploads\/IRS-Impostors-Phishing-Scam-Surge-Microsoft-Warns-29000-Users-Infected-with-RMM-Malware-1.jpg","_links":{"self":[{"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/posts\/1186701","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/comments?post=1186701"}],"version-history":[{"count":5,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/posts\/1186701\/revisions"}],"predecessor-version":[{"id":1200089,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/posts\/1186701\/revisions\/1200089"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/media\/1186705"}],"wp:attachment":[{"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/media?parent=1186701"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/categories?post=1186701"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/tags?post=1186701"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}