fbpx
Wednesday, 31 May 2023
La mansión de las ideas
  • Present
  • Money
  • SNAP
La mansión de las ideas

Home » Home & Crafts » Revealed Emotet Malware Disguised as IRS W-9 forms

Revealed Emotet Malware Disguised as IRS W-9 forms

The Emotet malware was disseminated through counterfeit W-9 tax documents supposedly originating from the IRS

by Nvindi
26/04/2023 13:28
in Home & Crafts
Revealed Emotet Malware Disguised as IRS W-9 forms

Revealed Emotet Malware Disguised as IRS W-9 forms

Noticias mas recientes del tema

Marie Kondo and Shoes: How to Store your Shoes Without Taking Up Too Much Room

Boost Your Savings Only Six EVs to Qualify for $7,500 Federal Tax Credit

Stop Overpaying on Property Taxes: How Minnesota Homeowners Can Challenge Their Assessments

U.S. taxpayers are currently being targeted in a fresh Emotet phishing campaign wherein fake IRS W-9 tax forms are being impersonated as originating from the Internal Revenue Service and companies that the victims work with. Emotet is a well-known malware that spreads through phishing emails containing harmful macros in Microsoft Word and Excel documents, thereby infecting systems.

Following Microsoft’s decision to block macros in Office documents downloaded from the internet by default, Emotet altered its tactics and began utilizing Microsoft OneNote files that contain embedded scripts to distribute and install the Emotet malware. Upon successful installation, Emotet has the ability to pilfer victims’ email addresses for future reply-chain attacks, send out more spam emails, and even deploy additional malware in the fake IRS W-9 that can offer initial entry points to other malicious actors like ransomware gangs.

Emotet prepares for the U.S. tax season targeting users with fake IRS W-9 tax form attachments

Themed phishing campaigns are frequently employed by Emotet to coincide with special events and annual business activities, including the ongoing U.S. tax season. Recently, security researchers at Malwarebytes and Palo Alto Networks Unit42 have observed new phishing campaigns launched by Emotet, targeting users with fake W-9 tax form attachments.

Revealed Emotet Malware Disguised as IRS W-9 forms
Revealed Emotet Malware Disguised as IRS W-9 forms

In one such campaign, observed by Malwarebytes, the threat actors send emails with the subject ‘IRS Tax Forms W-9,’ pretending to be an ‘Inspector’ from the Internal Revenue Service. The phishing emails are equipped with a compressed ZIP file labeled ‘W-9 form.zip’ that comprises a Word document embedded with malware. To evade detection by security software, the size of this malicious Word document has been artificially inflated to over 500MB.

Since Microsoft has started to block macros by default, users are less inclined to enable macros and consequently, are less susceptible to being infected via malicious Word documents. Brad Duncan from Unit42 has detected a phishing campaign that circumvents these safeguards by utilizing Microsoft OneNote files that contain embedded VBScript files to deploy the Emotet malware.

This phishing campaign comprises reply-chain emails impersonating business partners who claim to be sending W-9 Forms

The attached OneNote documents may appear to be protected, prompting users to double-click the ‘View’ button for proper viewing. However, concealed beneath this button is a VBScript document that will be executed instead. Upon launching the embedded VBScript file, Microsoft OneNote will display a warning message to the user, indicating that the file may be malicious. Regrettably, many users have disregarded these warnings in the past and proceeded with running the files.

Once executed, the VBScript will initiate the download of the Emotet DLL and execute it with the help of regsvr32.exe. The malware will now operate inconspicuously in the background, surreptitiously collecting emails and contacts while waiting for additional payloads to install on the device.

In the event that you receive any emails purporting to be W-9 or other tax forms, it is recommended that you initially scan the documents using your local antivirus software. Nonetheless, it is not advisable to upload these forms to cloud-based scanning services like VirusTotal due to the sensitive nature of their content. Typically, tax forms are disseminated as PDF documents and not as Word attachments. Therefore, it is advisable to abstain from opening such attachments and enabling macros if you receive them.

As always, the most effective defense is to delete any emails originating from unknown senders. If you do recognize the sender, it is prudent to contact them via phone first to verify if they indeed sent the email.

Tags: IRSMoney
Previous Post

Walmart Shutting Down Store Plagued by Persistent Theft in Washington and Costumers Should Find a New Place to Shop Now

Next Post

Accessing Nutritious Food Made Easier: A Guide to Applying for SNAP

Artículos Relacionados

6 states you may be eligible for the stimulus check money
Present

Stimulus Check Money: If you Live in One of These 6 States you May be Eligible

Piece of the Social Security Millions in June
Present

Social Security schedule in June: find out when will you be receiving your SSI and SSDI benefits

Payment of $914 From Social Security Will Arrive
Present

Social Security Check: $914 Payment Is Set to Arrive Tomorrow in June!

logo la mansion
  • Home & Crafts

© 2023 Mansion Ideas | Aviso Legal y Cookies | hoTTie

  • Present
  • Money
  • SNAP
Gestiona tu privacidad

To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.

Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.

Funcional Always active
El almacenamiento o acceso técnico es estrictamente necesario para el propósito legítimo de permitir el uso de un servicio específico explícitamente solicitado por el abonado o usuario, o con el único propósito de llevar a cabo la transmisión de una comunicación a través de una red de comunicaciones electrónicas.
Preferencias
El almacenamiento o acceso técnico es necesario para la finalidad legítima de almacenar preferencias no solicitadas por el abonado o usuario.
Estadísticas
El almacenamiento o acceso técnico que es utilizado exclusivamente con fines estadísticos. El almacenamiento o acceso técnico que es utilizado exclusivamente con fines estadísticos anónimos. Sin una requerimiento, el cumplimiento voluntario por parte de su proveedor de servicios de Internet, o los registros adicionales de un tercero, la información almacenada o recuperada sólo para este propósito no se puede utilizar para identificarlo.
Mercadeo
El almacenamiento o acceso técnico es necesario para crear perfiles de usuario para enviar publicidad, o para rastrear al usuario en un sitio web o en varios sitios web con fines de marketing similares.
Statistics

Marketing

Features
Always active

Always active
Manage options Manage services Manage vendors Read more about these purposes
Administrar opciones
{title} {title} {title}
  • English