Skip to content
Tax Authority Phishing Emails Demand "72-Hour Document Submission," Warning Issued ...

Tax Authority Phishing Emails Demand "72-Hour Document Submission," Warning Issued ...

Finance.Biggo July 19, 2026

Phishing emails impersonating tax authorities and preying on the anxiety of corporate personnel are being distributed. The moment a recipient clicks a link in the email body, a Chinese-developed remote-control program is secretly installed, potentially enabling the theft of PC screen content, files, and even audio data, warranting heightened caution.

East Security's Security Response Center (ESRC) announced on the 19th that phishing emails titled "Tax Violation and Sanction Notice" have recently been sent targeting corporate personnel in South Korea.

The attackers used overseas free webmail accounts while disguising the messages as official documents from a tax authority. The emails state that a violation of specific income tax law provisions has been confirmed, and that legal sanctions may follow if relevant materials are not submitted within 72 hours of receiving the notice. This is a classic social engineering hacking technique, using urgent content that would fluster any corporate representative to induce clicks.

When a recipient clicks the link in the email body, they are directed to the file-sharing service "LimeWire." A compressed file named "Tax Violation Code.zip" is downloaded, and upon decompression, executing the "Tax Violation Code.exe" file initiates the malware infection.

This executable file was applied with a valid code-signing certificate issued under an individual's name based in Liaoning Province, China. Analysts determined this allowed it to bypass Windows SmartScreen warnings and reputation-based detection by security programs.

Once the malware executes, "RdViewer," a commercial remote-control program developed by a Chinese company, is installed in a hidden path within the user account. Because this program registers itself as a legitimate Windows service, it automatically runs even after the computer is rebooted. After installation is complete, the initial executable file deletes itself, making it difficult for users to recognize the infection or for post-incident analysis to be conducted.

East Security's ESRC explained, "The installed remote-control program disguises itself as a system process and then connects to the attacker's command-and-control (C2) server, providing a pathway to access the PC screen, files, and audio." If infected, there is a high probability that attackers could remotely manipulate the PC or exfiltrate confidential corporate data.

The security industry points to two main characteristics of this attack. First, the malicious file was not directly attached to the email; only a link to a legitimate file-sharing service was delivered, bypassing the attachment scanning of email security systems. Second, the sensitive topic of tax violations and the short 72-hour submission deadline were used to maximize psychological pressure on recipients.

ESRC urged, "They used a method that lowers vigilance by combining emails disguised as actual agency documents with legitimate file-sharing services. Even if an email relates to tax or legal affairs, if it was sent from an address that is not an official agency domain, you should never execute links or attached files and must separately verify the notification directly through the relevant agency."

Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.

Extracted Entities