Urgent Phishing Campaign Targets Corporate Tax Personnel in South Korea

Urgent Phishing Campaign Targets Corporate Tax Personnel in South Korea

First seen 19 Jul 2026, 19:46 UTC BrecorderFinance.Biggo 71% similarity 71.0

Article Content

Browse articles
ThreatCluster

A phishing campaign targeting corporate personnel in South Korea has been uncovered, with emails impersonating tax authorities demanding urgent document submissions. The emails, titled 'Tax Violation and Sanction Notice,' create a sense of urgency by threatening legal sanctions if documents are not submitted within 72 hours. Upon clicking a link in the email, users unknowingly download a malware-laden file from a legitimate file-sharing service, LimeWire. This file installs a remote-control program, 'RdViewer,' developed in China, allowing attackers to access sensitive corporate data. The malware's use of a valid code-signing certificate enables it to bypass security measures, making detection difficult. East Security's Security Response Center (ESRC) has issued warnings about the campaign, emphasizing the psychological manipulation involved. The attack highlights the risks associated with urgent and sensitive topics in phishing attempts.

Key Points: • Phishing emails impersonate tax authorities, demanding urgent document submissions. • Malware installed via a link to a legitimate file-sharing service, LimeWire. • The remote-control program allows attackers to access sensitive corporate data.

ThreatCluster AI

Timeline

2026-07-17
Kaspersky warns of phishing targeting manufacturing facilities
Kaspersky reported a phishing campaign targeting manufacturing facilities in Asia and Europe, using emails from alleged buyers to extract corporate data.
Brecorder
2026-07-19
Phishing campaign targeting tax personnel revealed
East Security's ESRC reported phishing emails impersonating tax authorities demanding urgent submissions from corporate personnel in South Korea.
Finance.Biggo

Community

Browse all →