That tax form could be malware in disguise. Here's how to tell.

W-9-1-1.
By Alex Perry  on 
Silhouette of person holding phone over blue IRS background
Tax season is here. Don't make any mistakes. Credit: Rafael Henrique/SOPA Images/LightRocket via Getty Images

Tax season is stressful enough without bad actors trying to steal your data.

A report from BleepingComputer (citing work by the data security firms MalwareBytes and Unit42) over the weekend revealed the existence of a new malware campaign designed to fool people waiting for tax documents to show up in their inboxes. It appears to be tied to Emotet, a particular strain of malware that's been infecting computers since 2014.

How it works is simple: You get an email purporting to be from the IRS with an attached W-9 form for filling out tax filing information. It might come as either a ZIP file containing a Word document, or as a OneNote document.

Once you download the file, you might get a message saying that the document is protected, asking you to click a "view" button or enable certain settings to get access. Doing so is what puts the malware onto your computer.

According to these reports, there are a few telltale signs that you're being messed with if you get one of these emails. First, tax forms almost always come attached as PDF files, not Word or OneNote documents. Second, if you open up a ZIP attachment and find that the Word doc waiting for you is more than 500MB in size, it's probably got malware on it.

Mashable Light Speed
Want more out-of-this world tech, space and science stories?
Sign up for Mashable's weekly Light Speed newsletter.
By signing up you agree to our Terms of Use and Privacy Policy.
Thanks for signing up!

That's way too big for a normal Word doc, but not coincidentally, is the right size to fool your inbox's automatic malware scanning tools.

Check the email (including the email address of the sender) for any usual syntax or spelling errors. If someone is claiming to be from the IRS but doesn't have an email ending in ".gov," maybe hesitate before opening something they sent you. You always have the option of calling on the phone to confirm the legitimacy of what you've been sent, too.

Tax forms can be obtained from the IRS website.

It's unfortunate that we have to worry about these things during an already unpleasant time of the year, but that's the world we live in.

Topics Cybersecurity


Recommended For You
ChatGPT: How to make it read responses aloud
Illustration of talking woman and the ChatGPT app


How to talk to a human at the IRS
Two women on the phone.

21 of the best ChatGPT courses you can take online for free
ChatGPT on phone

The best MacBooks: Which Apple laptop would we buy in 2024?
2020 Apple MacBook Air with display on

More in Tech



Amazon deal of the day: The M3 MacBook Air just hit its lowest price on record
Bose earbuds, MacBook Air, and Fitbit Versa 4 with blue and purple squiggle background

Snag a 13-inch M3 MacBook Air at its lowest price yet
M3 MacBook Air on light blue abstract background

Trending on Mashable
NYT Connections today: See hints and answers for April 26
A phone displaying the New York Times game 'Connections.'

Wordle today: Here's the answer and hints for April 26
a phone displaying Wordle

NYT's The Mini crossword answers for April 26
Closeup view of crossword puzzle clues

Summer Movie Preview: Every film you oughta know
A composite of movie stills from summer movies.

NYT Connections today: See hints and answers for April 25
A phone displaying the New York Times game 'Connections.'
The biggest stories of the day delivered to your inbox.
This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.
Thanks for signing up. See you at your inbox!