Cybersecurity researchers at CYFIRMA have identified a sophisticated phishing campaign targeting Indian taxpayers with fake income tax assessment notices designed to install remote access malware on victim devices.
Key Points
- Attackers use a fraudulent website mimicking the official Indian Income Tax Department to pressure victims into downloading malicious ZIP archives.
- The malware utilizes a multi-stage infection process, including a loader and a disguised DLL file, to evade automated security detection.
- Once installed, the payload functions as a Remote Access Trojan, establishing encrypted communication with servers located in Hong Kong.
- The malicious infrastructure exhibits technical similarities to known threat families like XWorm, suggesting a financially motivated operation.
- Security experts advise verifying tax correspondence through official government portals and restricting the execution of unknown files from archives or disk images.