🚨 Tax Season, Scam Season: Lookalike Domains Target Spain’s Agencia Tributaria
Today (April 8), the tax filing and refund period officially starts in Spain — and as expected, so do the scams.
We’ve identified multiple new registrations of lookalike domains impersonating Spain’s official tax authority (Agencia Tributaria) happening over the past weeks, including:
agenciatributaria-gob[.]com
agencia-tributaria[.]im
agenciatributaria[.]de
sede-agenciatributaria[.]com
Threat actors moved so fast that some campaigns were launched before the official refund process even started, already promising generous (and obviously fake) tax refunds.
For example, agencia-tributaria[.]im advertises refunds of €250+ — a clear lure.
Laughs aside, while they may not be the smartest in terms of timing, they are learning new tricks. We’ve been talking a lot about TDSs lately, and they seem to like them too.
That same domain redirects users almost instantly to a malicious phishing landing page if they match the attacker’s targeting criteria. However, when accessed from a Linux virtual machine, fingerprinting likely flags a security analyst environment — and suddenly you’re redirected to the lovely and familiar "google[.]com" page, never seeing a second of the phishing content. The same seems to occur if you access it from another country.
They may have been fast starting their campaigns (maybe too fast)…but we’re faster finding them!
#dns #infoblox
#infobloxthreatintel
#threatintel
#threatintelligence
#cybercrime
#cybersecurity #phishing #scam
#spain #agenciatributaria #declaraciondelarenta