Threat Advisory

Threat actors strive to cause Tax Day headaches

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Researchers have noticed phishing attacks targeting accounting and tax return preparation organisations to spread the Remcos remote access trojan (RAT) and breach target networks. The campaigns are unusually focused and targeted, though social engineering tactics like this one have become common around Tax Day and other important national occasions. Only businesses that deal with tax preparation, financial services, CPA and accounting firms, and professional service companies that deal with bookkeeping and taxes are the focus of this threat. Remcos, which stands for "Remote Control and Surveillance", is a closed-source programme that lets threat actors remotely get administrator rights on Windows-based computers. Remcos and other offensive security solutions are marketed as genuine software by a European corporation. Remcos was one of the top malware variants in 2021, according to CISA, which stated its use in massive phishing attempts using COVID-19 pandemic themes that were directed at both organisations and individuals.[/subscribe_to_unlock_form]

Summary:

Researchers have noticed phishing attacks targeting accounting and tax return preparation organisations to spread the Remcos remote access trojan (RAT) and breach target networks. The campaigns are unusually focused and targeted, though social engineering tactics like this one have become common around Tax Day and other important national occasions. Only businesses that deal with tax preparation, financial services, CPA and accounting firms, and professional service companies that deal with bookkeeping and taxes are the focus of this threat. Remcos, which stands for "Remote Control and Surveillance", is a closed-source programme that lets threat actors remotely get administrator rights on Windows-based computers. Remcos and other offensive security solutions are marketed as genuine software by a European corporation. Remcos was one of the top malware variants in 2021, according to CISA, which stated its use in massive phishing attempts using COVID-19 pandemic themes that were directed at both organisations and individuals.[emaillocker id="1283"]

Remcos attack chain

The campaign employs enticements that appear to be tax documents given by a client and to avoid discovery, the link in the email makes use of a legitimate click-tracking service. After that, the actor uploads Windows shortcut (.LNK) files to a genuine file hosting website, redirecting the victim there. These LNK files send web requests to IP addresses or domains controlled by actors to download malicious files. In order to give the actor potential access to the target device and network, these malicious files perform tasks on the target device and download the Remcos payload. Researchers have noticed that the phishing email's link leads to Amazon Web Services. The target is then redirected from the initial link to a ZIP file that is stored on an authorized file-sharing service. LNK files, which serve as Windows shortcuts to other files, are included in the ZIP file. To download additional malicious files like MSI files containing DLLs or executables, VBScript files carrying PowerShell commands, or deceptive PDFs, the LNK files make web requests to actor-controlled domains and IP addresses. If a Remcos payload is successfully delivered, an attacker may have the chance to take control of the target device and steal data or move laterally over the target network.

Remcos is a closed-source program that allows attackers to remotely get administrator rights on Windows-based computers. The attackers employ various strategies to avoid detection, including the use of reputable file-sharing websites, cloud hosting services, and encryption and obfuscation. The attacks lead to potential data theft and lateral movement within the target network if a Remcos payload is successfully delivered.

Threat Profile:

References:

The following reports contain further technical details:

https://www.microsoft.com/en-us/security/blog/2023/04/13/threat-actors-strive-to-cause-tax-day-headaches/

[/emaillocker]
crossmenu