PDF and QR Code Phishing Attacks Spike Ahead of Tax Season, Microsoft Reports
Microsoft is warning about a series of phishing attacks using fake tax-related emails to spread malware and steal user credentials. These scams often include PDF attachments with shortened links or QR codes, which lead to fake websites that look like trusted services (e.g., DocuSign or Microsoft 365).
Some of these attacks use a platform called RaccoonO365, which helps cybercriminals create phishing websites. Once users click the links, they might be tricked into downloading malware like Latrodectus, Remcos RAT, GuLoader, AHKBot, and BRc4—tools that give attackers remote access or steal information.
Cybercriminals use tricks like QR codes, URL shorteners, and fake login pages to hide harmful links. They also abuse trusted platforms like Dropbox and Adobe to bypass security. Some emails pretend to be from services like Spotify or send fake alerts to steal login or payment info.
To stay safe, Microsoft recommends using phishing-resistant login methods, enabling web filters and network protections, and avoiding clicking on unknown links or attachments, especially during the tax season when these scams are more common.
Source: https://thehackernews.com/2025/04/microsoft-warns-of-tax-themed-email.html