Cybercriminals are intensifying their efforts to exploit taxpayers through sophisticated phishing campaigns.
These campaigns utilize tax-related themes as social engineering lures to steal credentials and deploy malware.
What distinguishes this year’s attacks is the increased use of redirection methods such as URL shorteners and QR codes contained in malicious attachments, allowing threat actors to bypass traditional security controls.
The phishing emails typically masquerade as official IRS communications, claiming to contain important tax information, refund eligibility notifications, or audit warnings.
When recipients interact with these seemingly legitimate communications, they unwittingly trigger complex infection chains that lead to credential theft or malware installation.
These attacks specifically target both individual taxpayers and tax preparation professionals, with a notable focus on CPAs and accounting firms in the United States.
Microsoft researchers identified several distinct campaigns between February and March 2025, affecting thousands of organizations primarily in the United States.
The attackers abuse legitimate services like file-hosting platforms and business profile pages to avoid detection while delivering payloads including remote access trojans (RATs), information stealers, and sophisticated post-exploitation frameworks such as BruteRatel C4.
One particularly concerning aspect of these campaigns is their multi-stage nature, designed to evade security solutions at each step.
.webp)
Initial emails often appear benign, establishing rapport with potential victims before delivering malicious content in subsequent communications.
This technique significantly increases click rates on malicious payloads due to the established trust between attacker and recipient.
QR Code Phishing Delivering RaccoonO365 Payloads
Between February 12 and 28, 2025, a notable phishing campaign targeted over 2,300 organizations across engineering, IT, and consulting sectors.
The campaign employed a particularly deceptive technique: emails with empty bodies containing PDF attachments with embedded QR codes.
When scanned, these QR codes directed victims to domains associated with the RaccoonO365 phishing-as-a-service platform.
The PDF attachments were uniquely generated for each recipient, with the QR code URLs including the target’s email address as a parameter, ensuring personalized tracking.
.webp)
The PDF contained a prominently displayed QR code with minimal surrounding text, increasing the likelihood that recipients would scan it without suspicion.
Unlike malicious attachments containing executable code that might trigger security warnings, QR codes appear innocuous to both users and many security solutions.
When scanned, they redirect to the attacker’s infrastructure at “shareddocumentso365cloudauthstorage[.]com” — a domain designed to mimic legitimate Microsoft services.
The RaccoonO365 platform provides sophisticated phishing kits that create convincing replicas of Microsoft 365 sign-in pages.
Once credentials are captured, attackers can use them for business email compromise, data exfiltration, or as a foothold for deploying additional malware.
The campaign’s use of various display names like “EMPLOYEE TAX REFUND REPORT” and “Tax Strategy Update Campaign Goals” further enhanced its effectiveness during tax season when such communications are expected.
Security experts recommend implementing phishing-resistant authentication methods, enabling Zero-hour auto purge in email security solutions, and educating users about the dangers of scanning QR codes from unsolicited emails, especially during high-risk periods like tax season.
Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try 50 Request for Free
