Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Incident: Cyber attack on Victoria’s court system may have exposed recordings of sensitive cases | ABC News Australia

    April 8, 2026

    How Secure by Design Helps Developers Build Secure Software

    April 8, 2026

    CVE-2026-4300 | THREATINT

    April 8, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Vimeo-Themed Phishing Campaign Targeting Personal and Banking Data
    News

    Vimeo-Themed Phishing Campaign Targeting Personal and Banking Data

    adminBy adminApril 8, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


      

    Cyber Threat Intelligence thumbnail

    The Center for Internet Security® (CIS®) Cyber Threat Intelligence (CTI) team has identified an ongoing phishing campaign impacting U.S. State, Local, Tribal, and Territorial (SLTT) entities in which threat actors masquerade as Vimeo video hosting platform support to harvest victims’ personal data, including banking details. Additionally, CIS CTI analysis showed very likely related threat actor infrastructure was using tax-themed phishing lures to deliver Datto remote monitoring and management (RMM) software for follow-on actions.

    This type of threat activity isn’t new. Threat actor abuse of legitimate RMM tools rose 277% between 2025 and 2026, according to Huntress. Additionally, in late March 2026, CIS CTI reported on another phishing campaign in which threat actors used tax-themed lures to trick users at U.S. SLTTs into clicking a TryCloudflare phishing link that automatically downloaded legitimate RemotePC software, another RMM technology product.

    CIS CTI was unable to observe the RMM impact directly in this newest phishing campaign, but as noted by Microsoft, RMMs like Datto grant threat actors persistent remote access to compromised devices and enable hands-on-keyboard activity, credential theft, and additional payload delivery.

    Analysis of the Vimeo-Themed Phishing Sample

    phishing sample iconInitial analysis stemmed from a Vimeo-themed phishing sample submitted by a member of the Multi-State Information Sharing and Analysis Center® (MS-ISAC®). CIS CTI’s analysis of the member-reported phishing sample (See Figure 1.) revealed the email passed Sender Policy Framework (SPF) as a designated sender for mg[.]vimeo[.]com, which is Vimeo’s Mailgun sending domain. Passing SPF for Mailgun indicates the threat actor sent the email through a legitimate Vimeo mail path, likely by abusing a Vimeo platform feature.

    The included link (https[:]//vimeo[.]verify389[.]live/255126394) was not active at the time of analysis, so CIS CTI directed its focus to the vimeo[.]verify389[.]live registered domain. VirusTotal relations for vimeo[.]verify389[.]live included a communicating file titled “Alice Support sent you a message on Vimeo – Vimeo – 2026-03-06 0844.eml” that contained nearly identical content to the original member-submitted sample. The sample pointed to the URL: https[:]//vimeo[.]verify389[.]live/253553798. The HTML contents of the URL indicated the page attempted to harvest victims’ credit card information, Social Security Number, date of birth, PayPal credentials, and other personal data.

     

    Figure 1 MS-ISAC member-submitted phishing sample

    Figure 1: MS-ISAC member-submitted phishing sample

    Broader Infrastructure Downloaded Datto RMM

    Additional analysis revealed a broader network of domains tied to verify389[.]live and staged to engage in similar social engineering efforts, including leveraging tax-themed lures. CIS CTI pivoted on the body SHA (a VirusTotal similarity hash of a webpage’s HTML content) hosted at http[:]//www[.]verify389[.]live/ to identify additional URLs:

    • https[:]//mytax-organizer[.]amosdadabooks[.]com/
    • https[:]//mytax-organizer[.]arpublication[.]com/
    • https[:]//mytax-organizer[.]noisetteroseproductions[.]com/de.php
    • https[:]//tax-filecenter-irs[.]matthewtarwater[.]com/de[.]php
    • https[:]//tax-filecenter[.]verrassendmykonos[.]nl/de[.]php
    • https[:]//bitbucket[.]org/guendennbvqplks638363638363863/ytrr/downloads/Documentation_T[…]95-0f66-4e61-85e7-52a5b86b551ce19f084b71dac5b410638bedc3efeb4f
    • https[:]//s3[.]us-east-2[.]amazonaws[.]com/vdjdj.thursfri/_EFIN_TRANSCRIPT_VIEWER_02_18_2026[.]exe?2fjGoQJf3h2fjGoQJf3h2fjGoQJf3h

    The matching similarity hashes indicate these URLs were built off nearly identical HTML structure, suggesting they are all very likely part of the same threat activity cluster or built from the same template.

    Identification of Tax-Themed Phishing Lures

    This was the first point at which CIS CTI identified tax-themed lures associated with this infrastructure. Running a passive DNS query identified 24 domains using mytax-organizer as a subdomain across varying registered domains and 14 domains using variations of tax-filecenter as a subdomain.

    The following hashes represent Datto RMM files downloaded from URLs hosted at various malicious domains, including mytax-organizer and tax-filecenter subdomains. The files are both signed as Datto RMM and contact legitimate Centrastage or Datto domains:

    • 9021c1b954334d1743eaf2b7ca3bab35227c7ac701d2c90de38713864c5792fa
    • efdb468a04e77d6cd0c55e6667ba0b370e5c0de6c6ad4f6c7507af2474d04182

    In addition to URLs containing variations of tax-filecenter and mytax-organizer subdomains, CIS CTI identified 94 URLs downloading these executables, including additional tax-themed URLs, Amazon Web Service (AWS) buckets, and Bitbucket URLs, suggesting broad malicious infrastructure abusing the Datto RMM. CIS CTI has since shared these domains in the MS-ISAC Real-Time Indicator Feeds and blocked the domains in the Malicious Domain Blocking and Reporting (MDBR) service.

    The overlaps across this infrastructure and tax-themed domains delivering Datto RMM indicate this is likely a broader financially motivated social engineering campaign exploiting tax season.

    Don’t Delay Your Cyber Defenses until Next Tax Season

    cyber defenses iconTo continually receive tailored mitigations and IOCs related to active cyber threats like the Vimeo-themed phishing campaign discussed above, you can join the MS-ISAC, a community dedicated to the Collective Cyber Defense of U.S. SLTTs. Members received early reporting on this phishing campaign, including over 1,000 IOCs through the CIS Indicator Sharing Program. Members also regularly receive support through services like MDBR, which at the time of publication has already blocked nearly 74,000 queries since March 26 to malicious domains associated with this campaign.

    Ready to counter tax-themed phishing lures through Collective Cyber Defense?

     



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleIncident: The Iconic promises refunds after a spate of fraudulent transactions on customer accounts | ABC News Australia
    Next Article Unauthenticated access to local configuration
    admin
    • Website

    Related Posts

    News

    How Secure by Design Helps Developers Build Secure Software

    April 8, 2026
    News

    XWiki CVE-2025-24893 Exploited in the Wild | Blog

    April 8, 2026
    News

    MS-ISAC Member-Reported Phishing Likely from Tycoon2FA PhaaS

    April 7, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Global Takedown of Massive IoT Botnets Halts Record-Breaking Cyberattacks

    March 20, 202619 Views

    Catchy & Intriguing

    March 17, 202619 Views

    The Grandparent Scam: How AI Voice Technology Makes This Old Con Deadlier Than Ever

    March 18, 202617 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Global Takedown of Massive IoT Botnets Halts Record-Breaking Cyberattacks

    March 20, 202619 Views

    Catchy & Intriguing

    March 17, 202619 Views

    The Grandparent Scam: How AI Voice Technology Makes This Old Con Deadlier Than Ever

    March 18, 202617 Views
    Our Picks

    Incident: Cyber attack on Victoria’s court system may have exposed recordings of sensitive cases | ABC News Australia

    April 8, 2026

    How Secure by Design Helps Developers Build Secure Software

    April 8, 2026

    CVE-2026-4300 | THREATINT

    April 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.