"Submit Documents Within 72 Hours": Prompting Execution
PC Can Be Remotely Controlled or Data Stolen If Infected

Caution is advised as phishing emails impersonating tax authorities and prompting recipients to install malware are being distributed.


According to Yonhap News on July 19, citing the East Security Security Response Center (ESRC), a phishing email titled "Tax Violation and Sanction Notice" was recently sent to representatives of domestic companies.


The photo is not directly related to the content of the article. Pixabay

The photo is not directly related to the content of the article. Pixabay

View original image

Rather than attaching a malicious file directly to the email, attackers used a link to a legitimate file-sharing service to evade security system detection. The email claimed that a specific provision had been violated during a tax audit and warned that, if the required documents were not submitted within 72 hours, sanctions could be imposed.


By clicking the link in the email, users download a file named "Tax Violation Code.zip" via a legitimate file-sharing service. When the compressed folder is extracted and the executable file is run, a malicious program installs "RdViewer," a remote-control program developed in China.


The executable file incorporates a valid code-signing certificate issued under an individual in Liaoning, China, designed to bypass Windows SmartScreen warnings and reputation-based security detection.


Once the malware is executed, the remote-control program installs itself in a hidden path within the user's account and registers as a normal program in Windows services, enabling it to start automatically even after a computer reboot. After installation, the original executable deletes itself, making it difficult for users to notice the infection or perform subsequent analysis.


Recently, a phishing email titled "Tax Violation and Sanction Notice" was sent to representatives of domestic companies. East Security Security Response Center (ESRC)

Recently, a phishing email titled "Tax Violation and Sanction Notice" was sent to representatives of domestic companies. East Security Security Response Center (ESRC)

View original image

ESRC explained that the installed remote-control program disguises itself as a system process and connects to the attacker's command and control (C2) server, providing a channel to access the PC’s screen, files, and audio. If infected, there is a possibility that attackers could control the PC remotely or exfiltrate internal data.


ESRC noted that the attack exploited fears by emphasizing a tax violation notice and a short deadline for submission, targeting corporate representatives’ anxiety. In particular, the email was crafted to resemble an official institutional document and employed a legitimate file-sharing service to lower recipients’ guard.



The center advised that, even if an email appears to concern tax or legal matters, if it is sent from an address not associated with an official institutional domain, users should not click links or open attachments, and must independently verify the notice with the relevant institution.


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing