Categorized | Antivirus

Persistent Tax Refund Scam

A month ago, the New Zealand Department of Inland Revenue (IRD) issued a warning advising people not to respond to scam emails claiming to offer tax refunds. We have observed these types of scams before, but the individual campaigns come and go. Like any other phishing scam, this email campaign appears to look like a legitimate notification from Inland Revenue complete with the logo.

IRD Tax refund scam email

The link in the message body points to a phony web page that mimics the New Zealand IRD website. But the odd thing is the instruction in a red font stating “Please click on your following bank logo to continue the refund procedure”.

Phishing page linking to various New Zealand bank

Clicking on any of the bank logos opens a fake login page that requires the user to enter their banking credentials and other personal details.

Fake NZ bank login page

While digging around the phishing site, we came across a “readme.txt” file. It basically left hints that this phishing page was a kit authored by “MaxDeMon” written specifically to target online banking users of a range of New Zealand banks.

Phishing kit "readme.txt" page

But Google searching some keywords from the phishing kit, it looks like the kit is used a lot and comes in different variations. Here is a screenshot of a fake “Tax Refund Portal” mimicking UK’s HM Revenue and Customs webpage, again instructing users to click on their bank logo:

Tax refund portal linking to a range of UK banks

The above suggests the ‘package’ is shared around, to be used by multiple groups. Such people only need a PHP web server (preferably a hacked web server) and to configure a PHP file to send phished banking information to their email address. That’s pretty easy, and probably why these type of phishing scams are persistent.

– Rodel Mendrez on M86 Security Labs Blog

Related Posts

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago