Security researchers reported multiple U.S.-focused phishing campaigns that used tax-themed lures to trick victims into opening password-protected ZIP archives and malicious Windows shortcut (.lnk) files. Microsoft said the activity targeted accounting, tax preparation, CPA, bookkeeping, and financial services firms, with emails posing as client tax documents and using AWS click-tracking links at awstrack[.]me to redirect users to hosted ZIP files. Securonix separately described a related campaign it tracks as TACTICAL#OCTOPUS, which used similar tax-season themes and staged lure PDFs to infect victims.
The infection chains relied on .lnk files to launch PowerShell and VBScript, retrieve additional MSI, DLL, EXE, and PDF payloads, and in some cases use GuLoader/CloudEyE to execute shellcode and deliver Remcos or other malware directly in memory. Securonix said newer samples shifted from encoded IP-based URLs to public redirect services such as rebrand.ly, while payloads used process injection into Internet Explorer utilities including ieinstal.exe and ielowutil.exe to evade detection. Researchers said the resulting compromises enabled remote access, keystroke logging, clipboard capture, information theft, and potential lateral movement, with observed command-and-control infrastructure including 5.8.8.100, 109.206.240.67, and 194.180.48.211.

Get the infrastructure and lures behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Securonix published research on TACTICAL#OCTOPUS, detailing tax-themed phishing against U.S. victims, the PowerShell/VBScript infection chain, GuLoader use in newer samples, and command-and-control infrastructure including Russian-registered IP space. The company said Russian origins were possible but attribution remained unconfirmed.
Microsoft publicly reported the Tax Day-themed phishing campaign and described how it delivered Remcos through Hightail-hosted ZIP files, malicious LNKs, and follow-on payloads including MSI, DLL, executable, VBScript, PDF, and sometimes GuLoader stages. The company also shared detections, indicators, and mitigation guidance.
An April 2023 update noted that newer TACTICAL#OCTOPUS samples moved from encoded IP-address URLs to public redirect services such as rebrand.ly. In the updated chain, samples directly downloaded and executed GuLoader/CloudEyE, which then hollowed into ieinstal.exe or ielowutil.exe after a short delay.
Microsoft observed a phishing campaign beginning in February that targeted accounting, tax preparation, CPA, bookkeeping, and financial services organizations with U.S. Tax Day-themed lures. The campaign used client-tax-document pretexts, AWS click-tracking links, ZIP archives, malicious LNK files, and in some cases GuLoader to deliver Remcos.
Securonix tracked an ongoing phishing and malware campaign it calls TACTICAL#OCTOPUS that targeted U.S. victims during the 2023 tax season using tax-themed emails and password-protected ZIP attachments. The infection chain relied on malicious LNK files, PowerShell and VBScript stages, and in-memory execution via Internet Explorer-related processes.
By the time of Securonix's reporting, the rebrand.ly redirect URLs used in the TACTICAL#OCTOPUS campaign had been blocked by the redirect service. This followed the campaign's shift to using public redirectors in newer samples.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 94 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
securonix.com
Open sourcemicrosoft.com
Open sourcecrowdstrike.com
Open sourceforensicitguy.github.io
Open sourcecrowdstrike.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.