Microsoft: IRS Phishing Attack Impacts 29K, Spreads RMM Malware
Mar 23, 2026 // 14:03 - Niko Dunn


Microsoft is alerting users to new schemes that are exploiting the upcoming U.S. tax season to steal login information and spread malicious software.

These email campaigns exploit the urgency and time-sensitive nature of tax season, sending phishing emails disguised as refund notifications, payroll documents, filing reminders, and requests from tax professionals. The goal is to trick people into opening harmful attachments, scanning QR codes, or clicking on suspicious links.

“Many scams aim to steal personal and financial information from individuals, while others specifically target accountants and professionals who handle sensitive documents, have access to financial data, and are used to receiving tax-related emails during this time,” the Microsoft Threat Intelligence and Microsoft Defender Security Research teams stated in their recent report.

Some of these scams direct users to fake websites created with Phishing-as-a-service (PhaaS) platforms, while others install legitimate remote monitoring and management tools (RMMs) like ConnectWise ScreenConnect, Datto, and SimpleHelp. This gives attackers ongoing access to infected devices.

Here are some details about these scams:

  • Using Certified Public Accountant (CPA) lures to present phishing sites linked to the Energy365 PhaaS kit, designed to steal email addresses and passwords. The Energy365 phishing kit is estimated to be sending hundreds of thousands of malicious emails every day.
  • Employing QR code and W2 lures to target around 100 organizations, mainly in manufacturing, retail, and healthcare in the U.S. These scams lead users to fake Microsoft 365 login pages built with the SneakyLog (aka Kratos) PhaaS platform, designed to steal login credentials and two-factor authentication (2FA) codes.
  • Creating tax-themed websites for phishing scams that trick users into clicking on fake links under the guise of accessing updated tax forms, which then distribute ScreenConnect.
  • Pretending to be the Internal Revenue Service (IRS) with a cryptocurrency lure specifically targeting higher education in the U.S. Recipients are instructed to download a “Cryptocurrency Tax Form 1099” from a malicious website (“irs-doc[.]com” or “gov-irs216[.]net”), which installs ScreenConnect or SimpleHelp.
  • Targeting accountants and related organizations, asking for assistance with tax filings via a malicious link that installs Datto.

Microsoft also reported a large-scale phishing attack on February 10, 2026, affecting over 29,000 users in 10,000 organizations. Approximately 95% of the targets were in the U.S., across sectors such as financial services (19%), technology and software (18%), and retail and consumer goods (15%).

“The emails imitated the IRS, claiming that potentially incorrect tax returns had been filed under the recipient’s Electronic Filing Identification Number (EFIN). Recipients were told to review these returns by downloading a supposedly legitimate ‘IRS Transcript Viewer,'” the company explained.

These emails, sent via Amazon Simple Email Service (SES), included a “Download IRS Transcript View 5.1” button. Clicking this button redirected users to smartvault[.]im, a website that mimicked SmartVault, a well-known document management and sharing platform.

The phishing site used Cloudflare to block bots and automated scanners, ensuring that only real users saw the malicious payload: a packaged version of ScreenConnect. This allows attackers to remotely access systems, steal data, gather credentials, and perform further actions after gaining access.

To protect against these attacks, organizations should enforce 2FA for all users, implement conditional access policies, monitor and scan incoming emails and visited websites, and prevent users from accessing malicious sites.

These developments coincide with the discovery of several campaigns designed to install remote access malware or steal data:

  • Using fake Google Meet and Zoom pages to entice users into fraudulent video calls that ultimately deliver remote-access software, such as Teramind (a legitimate employee monitoring tool), via a fake software update.
  • Using a fraudulent website that copies Avast’s branding to trick French-speaking users into providing their full credit card details as part of a refund scam.
  • Using a website with a deliberately misspelled address that looks like the official Telegram download page (“telegrgam[.]com”) to distribute infected installers. These installers not only install Telegram but also execute a DLL that launches a payload in memory. This payload then connects to a command-and-control server to receive instructions, download updates, and maintain persistent access.
  • Misusing Microsoft Azure Monitor alert notifications to send callback phishing emails that use invoice and unauthorized-payment lures. “Attackers create malicious Azure Monitor alert rules, embedding scam content in the alert description, including fake billing details and attacker-controlled support phone numbers,” LevelBlue explained. “Victims are then added to the Action Group linked to the alert rule, causing Azure to send the phishing message from the legitimate sender address [email protected].”
  • Using quotation-themed lures in phishing emails to deliver a JavaScript dropper. This dropper connects to an external server to download a PowerShell script, which launches the trusted Microsoft application “Aspnet_compiler.exe” and infects it with an XWorm 7.1 payload via reflective DLL injection. The updated malware includes a .NET component designed for stealth and persistence. Similar requests for quotation lures have also been used to trigger a fileless Remcos RAT infection.
  • Using phishing emails and ClickFix tactics to deliver NetSupport RAT, allowing attackers to gain unauthorized system access, steal data, and deploy additional malware.
  • Using Microsoft Application Registration Redirect URI’s (“login.microsoftonline[.]com”) in phishing emails to exploit trust relationships and bypass email spam filters, redirecting users to phishing sites that steal login credentials and 2FA codes.
  • Abusing legitimate URL rewriting services from Avanan, Barracuda, Bitdefender, Cisco, INKY, Mimecast, Proofpoint, Sophos, and Trend Micro to hide malicious URLs in phishing emails and avoid detection. “Threat actors have increasingly adopted multi-vendor chained redirection in their phishing campaigns,” LevelBlue stated. “Earlier activity typically relied on a single rewriting service, but newer campaigns stack multiple layers of already‑rewritten links. This nesting makes it significantly harder for security platforms to reconstruct the full redirect path and identify the final malicious destination.”
  • Using malicious ZIP files disguised as various software programs, including AI image generators, voice changers, stock-market trading tools, game modifications, VPNs, and emulators, to deliver Salat Stealer or MeshAgent, along with a cryptocurrency miner. This campaign has specifically targeted users in the U.S., the U.K., India, Brazil, France, Canada, and Australia.
  • Using digital invitation lures sent in phishing emails to redirect users to a fake Cloudflare CAPTCHA page. This page delivers a VBScript, which then runs PowerShell code to retrieve an evasive .NET loader called SILENTCONNECT from Google Drive, ultimately delivering ScreenConnect.

These findings follow a rise in RMM tool adoption by attackers, with abuse of these tools increasing by 277% year-over-year, according to a recent report by Huntress.

“Because legitimate IT departments use these tools, they are often overlooked and considered ‘trusted’ in most corporate environments,” noted Elastic Security Labs researchers Daniel Stepanic and Salim Bitam. “Organizations must remain vigilant and audit their environments for unauthorized RMM usage.”

#29k,  #attack  #impacts  #irs  #malware  #microsoft  #news  #phishing  #rmm  #spreads   —   News