Emotet Malware Sending Emails Disguised as IRS

Emotet Malware Irs Featured

What makes any malicious action successful is to be unsuspecting. While we’re all aware that we shouldn’t open email links from an unknown sender, when the sender is a trusted organization, it makes us feel safe enough to not even consider that there could be nefarious actions attached to it. That’s the case with a new Emotet campaign that disguises emails as being from the IRS – but they’re really hiding malware within.

Also read: Emotet Malware Targets US Government

What Is Emotet Malware?

Emotet is malware that infects computers by hiding in malicious emails. The malware is hidden in Microsoft Word and Excel files. When these files are opened, unsuspecting users unknowingly enable macros that trigger the Emotet malware to be downloaded onto the users’ computers.

Emotet Malware Irs Malicious File

The malware, once installed, steals the emails of users and stores them for use in future attacks. It also sends more spam emails and installs other malware that could lead to a ransomware attack.

But again, to be successful, the Emotet malware needs to find unsuspecting people or an unsuspecting way to launch the attacks.

Ransomware Pretending to Be IRS

The Emotet malware found its unsuspecting way to launch attacks during tax season. It’s very easy to assume the Internal Revenue Service letter you’re looking at in your email is real.

Security firm Cofense issued a report that showed the multiple phishing campaigns that were disguised as emails from the IRS. The recipients are tricked into believing the emails contain their tax return, W-9 form, or another relevant document.

Emotet Malware Irs Email
Image: Cofense

The letters contained in the emails and the subject line in the emails may differ, but ultimately, the overall message is that this is an important document you’ve been waiting for. The subjects have been “IRS Tax Forms,” “W-9 Incorrect Form Selection,” and “INCOME TAX RETURN 2021.”

An example directs recipients to a W-9 attachment and asks for it to be filled out and returned. It kindly offers answers to any questions and a “hard copy email,” which seems like an oxymoron.

Zip files or HTML files are attached to the emails. They get through secure email because they are password protected. This leads to an assumption that this is a group that knows what it’s doing.

Emotet Malware Irs Forms

Then again, in tests that were conducted, the files weren’t parsed correctly by the built-in extractor in Windows. And if the malware can’t be downloaded, the email won’t hold much weight. Third-party programs, though, don’t have a problem extracting the files.

Inside an example email is a “W-9 form.xslm” Excel file. After it’s opened by a user, they are asked to click the “Enable Editing” or “Enable Content” button to see the document. When the button is clicked, the micros will download and install the Emotet malware that’s waiting on WordPress sites that have been hacked.

Additional payloads will be downloaded once the Emotet malware is installed. These payloads have often been Cobalt Strike. Another research group, Cryptolaemus, has seen the SystemBC remote access Trojan being dropped by Emotet.

Emotet Malware Irs Laptop

Perhaps something similar is what happened to my husband and me. We filed our return a few years back through an online tax software, and we were informed someone with our names, address, and social security numbers had already filed our return. Neither of us had initiated a tax return other than that one. We had to jump through hoops to convince the IRS of our true identities.

We have not been fooled since and no longer file online. A note to the wise: the IRS won’t email you. It will contact you through the United States Postal Service. If you believe you may have been infected, learn how to check your PC for Emotet malware.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Laura Tucker Avatar

Read next

When the SS Great Eastern laid the first working transatlantic telegraph cable in 1866, a message that had taken ten days by steamship suddenly crossed the ocean in minutes, and the financial markets of London and New York were forced, within a single trading week, to invent the modern concept of synchronised global price.
The Big Ear telescope was scanning at 1420.4056 megahertz on the night of 15 August 1977, the exact frequency at which hydrogen atoms vibrate across the universe, because Giuseppe Cocconi and Philip Morrison had argued years earlier that any species trying to be found would broadcast on that channel — and then, for 72 seconds, something did.
In 2016, archaeologists dated two rings of snapped stalagmites in France’s Bruniquel Cave to 176,500 years ago, evidence that Neanderthals had walked 336 metres into darkness with fire and built architecture deep underground long before modern humans reached Europe
Otto von Bismarck was 74 when Germany adopted the world’s first national old-age social insurance program in 1889, setting the pension age at 70 after years of fighting socialists with bans, laws, and a promise few workers would live long enough to use
When cosmonaut Valeri Polyakov stepped out of his Soyuz capsule in March 1995 after 437 consecutive days aboard Mir, doctors recorded him at several centimetres above his pre-flight height, and his spine had become so unaccustomed to gravity that the recovery team carried him to a chair rather than risk the compression of letting him walk.
When Bell Labs engineer Karl Jansky pointed a rotating antenna at the sky in 1932 looking for sources of transatlantic radio static, he kept picking up a faint hiss that peaked every 23 hours and 56 minutes, and he eventually realized he had become the first human to hear the center of the Milky Way.
When Harvard astronomer Cecilia Payne submitted her 1925 doctoral thesis arguing that the Sun was made almost entirely of hydrogen, the field’s senior figure Henry Norris Russell talked her into adding a line calling the result ‘almost certainly not real,’ and then published the same conclusion himself four years later to widespread acclaim.
When seismic waves from the Chicxulub impact reached what is now North Dakota roughly ten minutes after the asteroid struck, they appear to have triggered a ten-metre standing wave in an inland river that flung fish onto the bank and buried them under glass beads still falling from the sky.