Trusted a 'Tax Violation' Notice Email... Warning Over Chinese Malware
"Submit Documents Within 72 Hours": Prompting Execution
PC Can Be Remotely Controlled or Data Stolen If Infected
Caution is advised as phishing emails impersonating tax authorities and prompting recipients to install malware are being distributed.
According to Yonhap News on July 19, citing the East Security Security Response Center (ESRC), a phishing email titled "Tax Violation and Sanction Notice" was recently sent to representatives of domestic companies.
Rather than attaching a malicious file directly to the email, attackers used a link to a legitimate file-sharing service to evade security system detection. The email claimed that a specific provision had been violated during a tax audit and warned that, if the required documents were not submitted within 72 hours, sanctions could be imposed.
By clicking the link in the email, users download a file named "Tax Violation Code.zip" via a legitimate file-sharing service. When the compressed folder is extracted and the executable file is run, a malicious program installs "RdViewer," a remote-control program developed in China.
The executable file incorporates a valid code-signing certificate issued under an individual in Liaoning, China, designed to bypass Windows SmartScreen warnings and reputation-based security detection.
Once the malware is executed, the remote-control program installs itself in a hidden path within the user's account and registers as a normal program in Windows services, enabling it to start automatically even after a computer reboot. After installation, the original executable deletes itself, making it difficult for users to notice the infection or perform subsequent analysis.
Recently, a phishing email titled "Tax Violation and Sanction Notice" was sent to representatives of domestic companies. East Security Security Response Center (ESRC)
View original imageESRC explained that the installed remote-control program disguises itself as a system process and connects to the attacker's command and control (C2) server, providing a channel to access the PC’s screen, files, and audio. If infected, there is a possibility that attackers could control the PC remotely or exfiltrate internal data.
ESRC noted that the attack exploited fears by emphasizing a tax violation notice and a short deadline for submission, targeting corporate representatives’ anxiety. In particular, the email was crafted to resemble an official institutional document and employed a legitimate file-sharing service to lower recipients’ guard.
Hot Picks Today
"Can't Get This in the U.S., Korea Is the Best": Americans Flock to Korea as 'K-Comprehensive Health Check-ups' Surge
- "Broke the Piggy Bank... Salaries Just Aren't Enough": The Stocks Individual Investors Are Rushing to Buy Worldwide
- "Rocket Eggs Emerge as Egg Prices Soar 40%... The Country Blaming College Entrance Exams"
- Korea Secures KRW 18.5 Billion Despite Group Stage Exit...Champion Spain to Receive KRW 75.4 Billion
- Chinese Group Tourists Abandoned from Noon to Evening After Refusing Shopping... Korea Embarrassed by ‘Low-Quality Tours Focused Only on Headcount’
The center advised that, even if an email appears to concern tax or legal matters, if it is sent from an address not associated with an official institutional domain, users should not click links or open attachments, and must independently verify the notice with the relevant institution.
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.