eFile.com
| Primary URL | Location | Industry | efile[.]com |
Country
United States of America
|
Financial Services
|
|---|
Profile
eFile.com operates as an IRS‑authorized tax filing service provider. It offers online tax return preparation and submission software for individual taxpayers and small businesses. The platform is designed to guide users through federal and state tax forms, calculations, and electronic filing with the Internal Revenue Service. Its primary market is the United States, where it serves customers during the annual tax filing season. The service emphasizes compliance with IRS standards and provides a secure channel for transmitting sensitive financial information. Users typically access the service through a web‑based interface that integrates with the IRS e‑file system.
In early 2023 the eFile.com website was compromised twice, with attackers injecting malicious JavaScript into legitimate pages. The first incident, discovered in February 2023, involved a modified Bootstrap component that displayed fraudulent SSL error messages to prompt visitors to download trojanized executables. Those executables established a persistent backdoor that allowed command execution, file retrieval, and potential lateral movement on infected systems. The infrastructure linked to the February attack was hosted on Alibaba cloud servers and used a valid digital certificate issued by a Sichuan‑based company, with activity attributed to suspected Chinese threat actors. A second compromise in March 2023 delivered similar JavaScript malware that fetched additional payloads from an external domain and installed a PHP‑based backdoor capable of remote command execution and data exfiltration. Security researchers noted that the malicious code remained active for weeks, exploiting the high traffic volume typical of tax season to reach a large number of visitors before remediation. Although no direct theft of tax data was confirmed in either incident, the attacks demonstrated the website’s attractiveness as a vector for distributing initial access malware during a period of heightened user engagement.
