Microsoft reported a wave of tax-season phishing campaigns targeting primarily U.S. organizations and individuals, using IRS-themed lures, fake tax documents, QR codes, malicious attachments, and abused legitimate services to steal credentials or deploy malware. One campaign attributed to Storm-0249 used IRS-themed emails and counterfeit DocuSign pages to deliver BruteRatel C4 and later Latrodectus, while other activity used QR-code PDFs to direct victims to RaccoonO365 credential-harvesting pages, malicious Excel macros to install AHKBot, and tailored outreach to accountants to deliver GuLoader and Remcos.
The activity shows attackers exploiting tax filing urgency and trust in government communications to compromise users and enterprise environments. Microsoft published indicators and mitigation guidance including MFA, phishing-resistant authentication, Safe Links, network protection, and Defender detections, while the IRS continues to direct the public to report fake IRS, Treasury, or other tax-related emails and messages through its phishing reporting channels.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
On March 3, 2025, Microsoft observed a tax-themed phishing campaign targeting CPAs and accountants in the United States with fewer than 100 emails. The attack began with a benign rapport-building message and, after the victim replied, progressed to a malicious PDF chain that installed GuLoader and then Remcos.
On February 13, 2025, Microsoft observed an IRS-themed phishing campaign targeting U.S. users with the subject 'IRS Refund Eligibility Notification.' The campaign abused a Google business open redirect to deliver a malicious Excel file that, if macros were enabled, installed AHKBot components and a screenshot-capturing module.
On February 6, 2025, Microsoft observed a phishing campaign attributed to Storm-0249 that sent several thousand tax-themed emails targeting the United States. The emails used IRS filing, audit, and unusual activity lures and led victims through redirect chains to fake DocuSign pages that delivered BruteRatel C4 and then Latrodectus.
Between February 12 and 28, 2025, Microsoft observed tax-themed phishing emails sent to more than 2,300 organizations, mostly in the United States and especially in engineering, IT, and consulting. The emails used empty bodies and PDF-embedded QR codes that directed victims to a RaccoonO365-linked credential phishing domain.
Microsoft said Latrodectus version 1.9 was first observed in February 2025. The version reintroduced scheduled-task persistence and command execution via cmd.exe.
Microsoft reported that it observed several tax-themed phishing and malware campaigns in early 2025 targeting primarily U.S. organizations and individuals as Tax Day approached. The campaigns used IRS and tax-document lures, QR codes, malicious attachments, and legitimate-service abuse to steal credentials or deploy malware including BruteRatel C4, Latrodectus, RaccoonO365, AHKBot, GuLoader, and Remcos.
At the end of January 2024, Microsoft Threat Intelligence observed a tax-season phishing campaign using employer-themed tax document lures. The emails carried HTML attachments that led victims to fake landing pages and then malicious executables that installed information-stealing malware to collect credentials and other sensitive data.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 26 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
microsoft.com
Open sourceblogs.technet.microsoft.com
Open sourceirs.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.