eFile tax website served malware to visitors for weeks

Posted:
in General Discussion
Just in time for tax season, the IRS-authorized eFile website prompted users to install a Windows botnet trojan through April 1.

eFile.com was serving malware
eFile.com was serving malware


Windows users that used eFile.com may have been exposed to a malicious JavaScript file prompting users to install a second-stage payload. While users would have needed to interact with this and install the .exe file, it is still recommended to run a virus scan.

According to a report from Bleeping Computer, Reddit users pointed out that the malware had been served since at least mid-march. It has been independently verified that eFile is no longer serving the malware as of April 4.

This affected the eFile website directly. Users that interacted with the service on a Windows PC will need to ensure their system is secure. Neither macOS nor iOS were not affected, but we're discussing the issue to bring awareness, given that the IRS has yet to make a formal statement about the issue, and millions of Americans could be affected.

A JavaScript file called popper.js was being loaded by nearly every page of eFile.com until at least April, the report confirmed. An additional file named update.js associated with the attack would prompt users to download the next stage of the payload, a Windows executable that changed based on which browser was in use -- Chrome or Firefox.

This malicious software was being served from a Tokyo-based IP address hosted with Alibaba. If installed, the trojan would act as a simple backdoor and turn the Windows machine into a botnet member.

The malware would connect to a remote command and control center every ten seconds to receive a task. And despite being a simple backdoor, it had full access to a device.

Antivirus products have reportedly already started flagging the executables as trojans. Again, we urge any Windows user that visited eFile.com in recent weeks to run a scan of their device.

Read on AppleInsider

Comments

  • Reply 1 of 4
    chasmchasm Posts: 3,308member
    Oh, but we're supposed to believe that the ONLY reason Macs are so resistant to malware is from "security through obscurity."

    Yeah, right ...

    PS. For our Windows friends: download the MalwareBytes free trial to do that scan.
    watto_cobra
  • Reply 2 of 4
    mystigomystigo Posts: 183member
    Whoa. That is pretty bad.
    watto_cobra
  • Reply 3 of 4
    mrstepmrstep Posts: 515member
    Is taxation still theft if they're offering free malware with it?
    watto_cobra
  • Reply 4 of 4
    baconstangbaconstang Posts: 1,108member
    Neither, nor are NOT affected?
    bart123ricDAalsethwatto_cobra
Sign In or Register to comment.