Tax-season social engineering is driving a spike in impersonation scams that use urgent “official notice” language to push victims into clicking links, opening attachments, or calling fake support numbers. One campaign spoofing the US Social Security Administration uses emails with subject lines like “Important Disclosures” and attachments masquerading as PDFs (e.g., Social_security_statements_2025.pdf) that instead deploy Datto RMM to establish remote access and can lead to RAT installation and full device control for data theft.
Separately, consumer-facing “Apple Security Alert” pop-ups/texts/emails claim a device is hacked or an Apple Pay transaction is under review and direct targets to call a listed phone number—an indicator of tech-support/payment fraud rather than a specific malware delivery chain. Broader reporting on tax scams cites survey data indicating an average victim loss of $1,020, increased perceived sophistication (including AI-enabled realism), and common lures across phone/email/text that pressure recipients to click links or send payments; this provides context on scale and victim impact but does not attribute to the specific SSA-themed malware campaign.

Get the infrastructure and lures behind it.
11 events from the most recent confirmed update back to the earliest known activity.
A phishing campaign targeting Indian taxpayers and businesses used a fake Income Tax Department portal and urgent tax-notice language to trick victims into downloading a malicious ZIP archive labeled as an assessment order. MalwareHunterTeam identified the domain zyisykm[.]shop on 2026-04-27, and reporting said the infection chain commonly used an NSIS-based dropper to install RATs and infostealers.
The Social Security Administration warned of a sharp increase in scam emails impersonating the agency and attempting to steal personal information or money through malicious links, fake websites, and malware-laced attachments. SSA said legitimate messages come from .gov addresses, said it never requests personal information or payment by email or text, and urged victims to report fraud to the Office of the Inspector General.
CIS CTI identified an ongoing phishing campaign targeting U.S. State, Local, Tribal, and Territorial entities that impersonated Vimeo support and used a legitimate Vimeo/Mailgun email path to steal personal and banking information. CIS linked the activity to tax-themed infrastructure, including mytax-organizer and tax-filecenter subdomains, and assessed it as part of a broader financially motivated social engineering campaign that could also deliver legitimate Datto RMM software for follow-on compromise.
Proofpoint reported that financially motivated threat actor TA2730 was running tax-season phishing campaigns focused on credential harvesting while impersonating firms such as Swissquote and Questrade. The report also described more than 100 tax-themed campaigns in 2026 abusing legitimate RMM tools and affecting users in the United States, Canada, Australia, Switzerland, and Japan.
Proofpoint reported that newly designated threat actor TA4922 was using tax-authority impersonation, out-of-band social engineering, and Winos4.0/ValleyRAT malware in campaigns primarily targeting Japan and other East Asian regions. The disclosure expanded the tax-scam narrative beyond North America and added a new attributed threat actor to the story.
CIS CTI reported an ongoing phishing campaign targeting U.S. State, Local, Tribal, and Territorial government entities with IRS- and Social Security-themed tax lures. Victims who clicked TryCloudflare-hosted links automatically downloaded legitimate RemotePC software, potentially giving attackers full remote access, and at least one lure redirected users to the official IRS website to appear legitimate.
A scam campaign targeting thousands of people in the United States impersonated the Social Security Administration with urgent emails about tax-related documents. The messages lured recipients into opening a fake PDF that instead used Datto RMM to help install a remote access trojan and enable device takeover and data theft.
McAfee's 2026 Tax Season Survey found broad concern about tax fraud in the US, with many people reporting contact from scammers posing as the IRS or other tax authorities by phone, email, or text. The survey also noted that many respondents believed AI had made the scams more realistic and effective.
Cybersecurity experts warned that AI-generated tax scams impersonating the Canada Revenue Agency were increasing in Canada. The warning highlighted a broader rise in more convincing tax-fraud lures during tax season.
Microsoft said a large-scale phishing campaign on 2026-02-10 impersonated the IRS and affected more than 29,000 users across 10,000 organizations, primarily in the United States. The operation used a fake SmartVault-themed site protected by Cloudflare to distribute a malicious ConnectWise ScreenConnect package for persistent access.
McAfee identified malicious or suspicious tax-themed domains that mimicked official government sites and were created during the run-up to tax season. These domains were used to steal credentials, identity data, payment information, or charge fraudulent fees.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 39 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
12 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceonlinethreatalerts.com
Open sourceonlinethreatalerts.com
Open sourcecisecurity.org
Open sourcethehackernews.com
Open sourcehackread.com
Open sourcezdnet.com
Open sourceglobalnews.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.