{"id":11889,"date":"2022-03-24T10:38:11","date_gmt":"2022-03-24T10:38:11","guid":{"rendered":"https:\/\/myonlinesecurity.co.uk\/?p=11889"},"modified":"2023-04-05T13:09:11","modified_gmt":"2023-04-05T13:09:11","slug":"spoofed-irs-urgent-notification-malspam-delivers-ransomware","status":"publish","type":"page","link":"https:\/\/myonlinesecurity.co.uk\/spoofed-irs-urgent-notification-malspam-delivers-ransomware\/","title":{"rendered":"Spoofed IRS Urgent Notification Malspam Delivers Ransomware"},"content":{"rendered":"

Continuing with the never ending series of malware downloaders is an email with the subject of IRS Urgent Notification coming or pretending to come from Dick Richardson who pretends to be an IRS Tax Officer. I have seen dozens of these and they all come from random email addresses. Dick Richardson changes his job in different emails. Sometimes he is a tax officer or a Tax Specialist or Tax department manager as well as an official representative<\/p>\n

These must obviously be aimed at US recipients because The UK does not have an IRS service, we have HMRC. But after following the link and downloading the zip file, you are redirected to the UK gov.uk home page. Anyway, this looks like some sort of ransomware from the virustotal reports, but I am not 100% sure which one.<\/p>\n

Update: I am reliably informed this is Shade\/ Troldesh ransomware<\/p>\n

Other subjects include:<\/p>\n