2023-04-04
Malicious JavaScript Detected on US Tax-filing Website
For at least the last two weeks, the IRS authorized e-filing provider eFile<dot>com's website has been compromised and occasionally offering malware to its customers. The website is serving a modified JavaScript file that includes content from the attacker's website. This content is used to direct the site’s customers to a fake error page which will instruct them to install a browser update that turns out to be a remote access trojan.
Editor's Note
Despite multiple attempts to contact efile<dot>com after we found the issue with their site, the malware is still present as of this morning.
Johannes Ullrich
As Johannes states in his analysis, it can be really difficult to detect when a trusted partner site gets compromised. Because of that existing trust, users are less likely to contemplate content carefully. This is where your boundary protections, EDR, and other layered defenses come into play. Leverage the IOCs in the ISC posting to ensure none of your users were captured. Consider reaching out to your CPA to make sure they are aware of this issue so they can take steps to mitigate the risks.
Lee Neely
A good reminder that business cycles drive risk levels – from January 1 to mid-April, tax filer companies have more risk of business impact. Just as flower companies and soap-on-a-rope companies have work at risk before Mother’s Day and Father’s day. That medium severity CVSS vendor vulnerability score can turn critical when you add the Temporal factor.
John Pescatore
Never discount the ingenuity of evil-doers to separate a target’s ‘money’ from their wallet. Unfortunately, and way too often, legitimate websites are compromised and taken-over to enable an attack. Given that we’re currently in tax season here in the US, it stands to reason that sites offering tax services would be targeted. It appears that eFile<dot>com needs to redouble its efforts at basic cyber hygiene for its website. A good place to start is implementing IG1 from the CIS Critical Security Controls.