Tax Season Phishing and Malware Campaign Targets Indian Taxpayers via Fake Income Tax Department Notices — Threadlinqs Intelligence
As of 2026-07-30, Tax Season Phishing and Malware Campaign Targets Indian Taxpayers via Fake Income Tax Department Notices is a high-severity malware threat attributed to Unknown (unattributed, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 53 indicators of compromise.
Threat ID: TL-2026-1769 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Unknown (unattributed · FINANCIAL
A coordinated, resourced campaign impersonates India's Income Tax Department, distributing the Windows credential-stealer ITD_Tax_Notice.exe and an Android APK dropper (ITD.zip) via WhatsApp messages
CloudSEK researchers (Shobhit Mishra, Jainam Shah) documented an active, live campaign exploiting India's Income Tax Return (ITR) filing season to distribute credential-stealing malware and run parallel social-engineering fraud against Indian taxpayers. The primary infection vector is WhatsApp: victims receive a bilingual (Hindi/English) fake 'Office Memorandum' penalty notice citing Sections 271(1)(c) and 276C of the Income Tax Act, 1961, spoofing a signatory ('Raj Kumar Sharma, Assistant Commissioner of Income Tax') and imposing a 72-hour compliance deadline to pressure victims into clicking a 'Download Documents' link.
That link resolves to one of 30+ disposable domains registered on cheap TLDs (.lol, .xin, .club, .lat, .ink, .shop, .click, .study, .bar, .cc, .live, .autos) using randomized consonant strings, each cloning official Income Tax Department page layouts and logos. Clicking through delivers either ITD_Tax_Notice.exe (Windows, PE32 GUI, Intel 80386, 3,265,096 bytes) or an ITD.zip archive containing a malicious Android APK (observed sample sizes 2 MB and 34-35 MB). The Windows binary is digitally signed with a legitimately-issued but abused Certum Extended Validation Code Signing 2021 CA certificate (serial 2D85A7A16D1EB86DFD92B00F6267733D), registered to a Chinese sole proprietor in Linyi, Shandong. The binary's PE version metadata falsely claims an original filename of svchost.exe and publisher 'Microsoft Windows' to blend in with legitimate system processes.
On execution, the dropper performs modified sleep-timing checks and virtualization/sandbox detection, then conducts registry, security-software, and system-information reconnaissance before deliberately exiting into Windows Error Reporting to frustrate automated analysis. It retrieves a second-stage payload (88.bin) from an Alibaba Cloud OSS bucket in Hong Kong (vss2.oss-cn-hongkong.aliyuncs.com, resolving to 47.79.66.58); the .bin file's near-maximum entropy (~8.0) and writeable .text section are consistent with in-memory shellcode/encrypted-blob execution designed to evade on-disk scanning. The malware additionally queries the legitimate geolocation service ipwho.is to profile victims. Combined Windows/Android capabilities documented by CloudSEK include SMS/OTP interception, credential and contact harvesting, keystroke logging, and overlay screens injected over banking and payment apps to steal login credentials -- consistent with TTPs seen in other Indian tax-themed Android banking trojans such as Drinik.
The malware operation sits inside a broader, coordinated fraud ecosystem targeting the same ITR filing season: fake refund SMS messages claiming refunds are 'pending, delayed, incomplete, or stuck'; fraudulent e-PAN emails offering fake e-PAN downloads or demanding manual document 're-verification' to release a refund (corroborated by India's PIB Fact Check unit, which separately warned of fake 'Download e-PAN Card Online' emails); cloned e-Filing portal pages replicating incometax.gov.in's layout to harvest credentials; and scam tax consultants who guarantee inflated refunds before reviewing actual income/TDS data, then either disappear with collected fees, harvest login/financial data, or file bogus deductions on the victim's behalf. CloudSEK assesses the operation as 'deliberate and sustained rather than opportunistic' based on the scale of registered infrastructure and resourcing, though it does not attribute the campaign to a named threat actor or nation-state; no CVE or CVSS applies, as no software vulnerability is exploited -- the chain is entirely social-engineering and malware-delivery based.
Target sectors: consumer, finance, government administration, professionalservices, smallbusiness
Target regions: india, South Asia
Detections & IOCs
As of 2026-08-07, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 53 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1583, T1608, T1588, T1566, T1204, T1497, T1574, T1055, T1027