Hackers Exploit U.S. Tax Season With Malvertising That Disables Antivirus Software and Installs Remote-Access Tools
During the U.S. tax-filing season from January through April each year, taxpayers and accountants frequently download documents such as W-2 and W-9 forms, making them prime phishing targets. The latest campaign impersonates forms associated with the Internal Revenue Service and abuses Google ads to broaden its reach, potentially compromising tax data and corporate endpoints.
During the 2026 tax season, around the April 15 filing deadline, hackers used malicious Google ads to direct victims to fake websites and trick them into downloading infected forms. The malware employs “double obfuscation” to evade scanning, uses BYOVD techniques to disable antivirus software and EDR, and installs remote management tools. Microsoft has issued a warning, but the number of victims and the amount of losses have not been disclosed.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.