Antivirus
Cybersecurity

That tax form could be malware in disguise. Here's how to tell.

W-9-1-1.
By Alex Perry  on 
Silhouette of person holding phone over blue IRS background
Tax season is here. Don't make any mistakes. Credit: Rafael Henrique/SOPA Images/LightRocket via Getty Images

Tax season is stressful enough without bad actors trying to steal your data.

A report from BleepingComputer(opens in a new tab) (citing work by the data security firms MalwareBytes(opens in a new tab) and Unit42(opens in a new tab)) over the weekend revealed the existence of a new malware campaign designed to fool people waiting for tax documents to show up in their inboxes. It appears to be tied to Emotet(opens in a new tab), a particular strain of malware that's been infecting computers since 2014.

How it works(opens in a new tab) is simple: You get an email purporting to be from the IRS with an attached W-9 form for filling out tax filing information. It might come as either a ZIP file containing a Word document, or as a OneNote document.

Once you download the file, you might get a message saying that the document is protected, asking you to click a "view" button or enable certain settings to get access. Doing so is what puts the malware onto your computer.

According to these reports, there are a few telltale signs that you're being messed with if you get one of these emails. First, tax forms almost always come attached as PDF files, not Word or OneNote documents. Second, if you open up a ZIP attachment and find that the Word doc waiting for you is more than 500MB in size, it's probably got malware on it.

That's way too big for a normal Word doc, but not coincidentally, is the right size to fool your inbox's automatic malware scanning tools.

Check the email (including the email address of the sender) for any usual syntax or spelling errors. If someone is claiming to be from the IRS but doesn't have an email ending in ".gov," maybe hesitate before opening something they sent you. You always have the option of calling on the phone to confirm the legitimacy of what you've been sent, too.

Tax forms can be obtained from the IRS website(opens in a new tab).

It's unfortunate that we have to worry about these things during an already unpleasant time of the year, but that's the world we live in.

More in Cybersecurity


Recommended For You
Gear up to blow your tax refund on these awesome deals


Beware of the tax advice you're getting on TikTok

Which dating app should you use? This guide can help you figure it out.

Misfits Market: An eco-friendly grocery delivery service that's good, but could be great

More in Tech
Google Bard introduces new features for generating and debugging code

Why you should consider going green with your gadgets this Earth Day and every day
By Mashable BrandX and HP

Rihanna, Taylor Swift among the few celebrities paying Twitter to keep their blue checkmarks

Avast show us what to expect In 2023 and how to stay safe


Trending on Mashable

'Wordle' today: Here's the answer, hints for April 21

Dril and other Twitter power users begin campaign to 'Block the Blue' paid checkmarks

How to remove Snapchat's My AI from your Chat feed

The biggest stories of the day delivered to your inbox.
By signing up to the Mashable newsletter you agree to receive electronic communications from Mashable that may sometimes include advertisements or sponsored content.
Thanks for signing up. See you at your inbox!