Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip Android APK + Certum-Signed ITD_Tax_Notice.exe Loader), Cloned e-Filing Portals and Refund Scams

Tax-Themed Phishing and Malware Campaign Targeting Indian (TL-2026-2654) is a high-severity phishing campaign, first published 2026-09-25. It has no confirmed attribution, affects N/A (social engineering) Indian taxpayers / ITR filers (individuals), maps to 18 MITRE ATT&CK techniques (T1012, T1027.002, T1036.005), and is covered by 9 detection rules and 28 indicators of compromise.

Key facts for TL-2026-2654

Threat ID
TL-2026-2654
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-09-25
Last reviewed
2026-09-25
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
finance, government administration, smb
Target regions
india, South Asia
Detection rules
9
Indicators of compromise
28

CloudSEK (published 30 Jul 2026) documents a sustained, resourced, financially motivated phishing/malware campaign against Indian taxpayers during ITR season. Threat actors deliver forged Income Tax Department 'Office Memorandum' penalty notices (citing Sections 271(1)(c) and 276C of the Income Tax Act 1961 with a 72-hour deadline) over WhatsApp as an Android APK capable of SMS/OTP interception, contact harvesting, keylogging and banking-app overlays, and via 30+ lookalike domains distributing a Certum EV code-signed Windows loader (ITD_Tax_Notice.exe, MD5 dff2b7a23882445b4e354199bf38554f) that masquerades as svchost.exe and pulls an in-memory second stage (88.bin) from an Alibaba Cloud OSS host (47.79.66.58). Parallel scams include fake refund messages, cloned e-Filing portals and fake tax consultants.

How Tax-Themed Phishing and Malware Campaign Targeting Indian works

CloudSEK threat researchers (Shobhit Mishra, Jainam Shah) documented a deliberate and sustained phishing and malware campaign targeting Indian taxpayers during the ITR filing season, published 30 July 2026 as 'Tax Season, Open Season'. No CVE is associated and no named threat-actor group is identified; the report characterises the effort as resourced and financially motivated rather than opportunistic, pointing to precise bilingual lure documents, real legal citations, and active payload rotation. The Income Tax Department of India does not serve statutory notices, penalty orders or summons over WhatsApp, which is the campaign's primary delivery channel.

The primary lure is a forged bilingual (Hindi/English) 'Office Memorandum' from the 'Income Tax Department of India, Aayakar Bhawan, New Delhi 110001', carrying the Government of India emblem, citing Section 271(1)(c) and Section 276C of the Income Tax Act 1961, demanding action within a 72-hour deadline, signed by a spoofed 'Raj Kumar Sharma, Assistant Commissioner of Income Tax' with a fabricated file number (e.g., No. TAX/PEN/2026-142). The notice is delivered by WhatsApp from unknown or compromised accounts flagged by the app as 'Not a contact'; observed sender display names include 'Sunil sharma', 'jankiforex' and 'Hotel Oyster' (none related to tax administration), and one sample was pushed inside a group chat. The attachment is ITD.zip, observed at three rotating sizes (2 MB, 34 MB, 35 MB) to defeat static signature detection. On mobile the payload is a malicious Android application (APK) that reads and intercepts SMS (banking OTPs), harvests contacts to spread further, captures keystrokes, and overlays fake screens on top of banking and payment apps to steal credentials.

A parallel web vector uses 30+ lookalike/disposable domains on cheap low-trust TLDs (.lol, .xin, .ink, .autos, .club, .lat, .study, .bar, .one, .shop, .click, .cc, .live, .com) to host forged Office Memorandums and cloned e-Filing portals that replicate the official incometax.gov.in look and harvest PAN, Aadhaar, password, OTP and bank-account details. The report stresses that stolen PAN alone is dangerous (it can be used to open accounts, apply for loans or launder money). For desktop/WhatsApp Web users, the same campaign distributes a signed Windows loader, ITD_Tax_Notice.exe (PE32 GUI, Intel 80386, 3,265,096 bytes; MD5 dff2b7a23882445b4e354199bf38554f; SHA-1 7479fbc27320ae246db9030cca80809ec63de0e9; SHA-256 667b37eafb9ec5131ed4f017ed429a47dca3adf626b2fc85fc6424b1e17ff6e1; import hash 538ad8e0ad1fec0ecc54f9e120ac6ff9). It is signed with a Certum Extended Validation Code Signing 2021 CA certificate (serial 2D85A7A16D1EB86DFD92B00F6267733D) issued to a Chinese sole proprietor in Linyi, Shandong, CN, and its version metadata claims the original filename svchost.exe, description 'Service Host', publisher 'Microsoft Windows'. The binary shows near-maximum entropy (~8.0) with a writeable .text section indicating a runtime packer. On detonation it fingerprints the machine via the ipwho.is geolocation service (a legitimate service abused for victim profiling and sandbox filtering), fetches a second-stage payload 88.bin from the Alibaba Cloud OSS bucket vss2.oss-cn-hongkong.aliyuncs.com (IP 47.79.66.58) and runs it in memory (shellcode or an encrypted blob), exhibits modified sleep behaviour and virtualisation/sandbox checks, performs registry, security-software and system-information reconnaissance, and ultimately exits into Windows Error Reporting. Only two network endpoints are observed, both legitimate services abused as infrastructure.

The report situates this within a wider tax-scam ecosystem active in the same season: (1) fake refund SMS/email/WhatsApp messages claiming a refund is pending/delayed/stuck and linking to fake e-Filing pages that harvest PAN, login credentials, OTPs and bank details; (2) cloned e-Filing portals harvesting PAN/Aadhaar/password/OTP/bank account numbers; (3) fake e-PAN or 'manual verification' emails (already flagged by India's PIB Fact Check) using 'Hello Taxpayer'/'Dear User' greetings and unexpected attachments; and (4) fake tax consultants/refund agents promising fast or inflated refunds, then collecting fees and vanishing or harvesting credentials. Refund-scam variants can end in account takeover, with scammers changing the victim's linked bank account to divert actual refunds. Related but separate tax-assessment phishing campaigns documented in the same period deliver commodity RATs (XWorm) via .NET loaders (e.g., harivo.vip hosting Tax_Assessment_0609.zip with libsvcs.dll, C2 103.231.12.27:4444) and in-memory malware (CYFIRMA 'Operation TaxShadow').

Defenders should treat the durable pattern as the signal: random consonant strings on cheap TLDs with no relation to any government namespace and a single call to action to download a file. Genuine Income Tax Department notices appear only inside a taxpayer's account on the official e-Filing portal (incometax.gov.in) and are verifiable via the Document Identification Number (DIN); the department never asks for OTPs, passwords or bank details. Reporting channels include the national cybercrime helpline 1930, the official cybercrime portal, webmanager@incometax.gov.in (for phishing emails/websites) and incident@cert-in.org.in.

MITRE ATT&CK techniques used in TL-2026-2654

Discovery

T1012 Query Registry; T1082 System Information Discovery; T1518.001 Security Software Discovery

Defense Evasion

T1027.002 Software Packing; T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1497 Virtualization/Sandbox Evasion; T1574.001 DLL

Credential Access

T1056.001 Keylogging

Command and Control

T1071.001 Web Protocols

Execution

T1204.001 Malicious Link; T1204.002 Malicious File

Initial Access

T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains; T1583.006 Web Services; T1588.004 Digital Certificates

Collection

T1636.004 SMS Messages

Affected products and versions in Tax-Themed Phishing and Malware Campaign Targeting Indian

  • N/A (social engineering) — Indian taxpayers / ITR filers (individuals)
  • N/A (social engineering) — Businesses and finance/HR teams receiving compliance-notice lures
  • Android — Android devices (malicious APK sideload)
  • Microsoft — Windows (ITD_Tax_Notice.exe loader)

Remediation for Tax-Themed Phishing and Malware Campaign Targeting Indian

Patches

  • No vendor CVE patch applies; keep Android/Windows OS and AV/EDR signatures current and enable Google Play Protect real-time scanning

Immediate actions

  • Treat any tax notice or refund message delivered via WhatsApp, SMS or email as potentially fraudulent; the Income Tax Department does not serve notices over WhatsApp
  • Do not open ITD.zip attachments, tap 'Download Documents' buttons, or sideload APKs from unofficial sources
  • Verify any notice's Document Identification Number (DIN) at incometax.gov.in and check messages only inside the official e-Filing portal
  • Never share OTPs, passwords, PAN/Aadhaar numbers or bank details in response to tax communications
  • Block the listed lookalike domains and the staging host vss2.oss-cn-hongkong.aliyuncs.com at the perimeter

Workarounds

  • If ITD.zip was opened, disconnect the device, change passwords from a clean device, enable MFA, run a full malware scan, and monitor bank- and PAN-linked accounts
  • Report incidents to the national cybercrime helpline 1930 or the official cybercrime portal; forward phishing emails to webmanager@incometax.gov.in and incident@cert-in.org.in

Longer-term hardening

  • Run short awareness briefings for staff during ITR filing season, especially finance and HR teams who receive compliance-notice lures
  • Block newly registered and low-trust TLDs (.lol, .xin, .ink, .autos, .club, .lat, .study, .bar, .one, .shop, .click, .cc, .live) at the gateway
  • Flag inbound archives (ZIP, disk images) and web-style files; watch for unusual svchost.exe paths, hidden system folders and unexpected outbound connections
  • Enable MFA and set daily UPI/transaction limits to contain credential theft and account draining
  • Deploy EDR/behavioral detection for in-memory payloads, process injection and packing

Weaknesses (CWE) in Tax-Themed Phishing and Malware Campaign Targeting Indian

CWE-494, CWE-522

Timeline of Tax-Themed Phishing and Malware Campaign Targeting Indian

  • PIB Fact Check flags fake Income Tax demand-notice emails (AY 2025-26 'compliance gaps' and Rs 6,000-demand variants); ITD reiterates it never asks for OTPs, passwords or bank details and that legitimate notices are verifiable via DIN on the e-Filing portal.
  • Analysts document a related Income Tax Assessment Notice phishing campaign delivering XWorm RAT via harivo.vip (Tax_Assessment_0609.zip, .NET loader, libsvcs.dll, C2 103.231.12.27:4444); CYFIRMA separately publishes 'Operation TaxShadow' in-memory tax-phishing research.
  • CloudSEK rates the campaign as deliberate and sustained rather than opportunistic, citing precise bilingual lure documents, real legal citations, and active payload rotation.
  • Sandbox analysis of ITD_Tax_Notice.exe: Certum EV code-signed (Linyi, Shandong CN), masquerades as svchost.exe, near-maximum entropy runtime packer; fingerprints machine via ipwho.is, fetches 88.bin from vss2.oss-cn-hongkong.aliyuncs.com (47.79.66.58), runs it in memory, modified sleep behaviour, registry/security/system recon, exits to Windows Error Reporting.
  • Android APK analysis: reads/intercepts SMS banking OTPs, harvests contacts, captures keystrokes, and overlays fake screens on banking and payment apps to steal credentials.
  • 30+ lookalike domains on 14 low-trust TLDs (.lol, .xin, .ink, .autos, .club, .lat, .study, .bar, .one, .shop, .click, .cc, .live, .com) host forged memoranda and cloned e-Filing portals; fake refund SMS/email and fake tax-consultant variants active.
  • Delivery from at least three unknown/compromised WhatsApp accounts flagged 'Not a contact' (display names 'Sunil sharma', 'jankiforex', 'Hotel Oyster'); one sample pushed inside a group chat.
  • Fake notices observed citing Sections 271(1)(c) and 276C of the Income Tax Act 1961 with a 72-hour deadline, spoofed signatory 'Raj Kumar Sharma, Assistant Commissioner of Income Tax', file No. TAX/PEN/2026-142, bilingual Hindi/English with the Government of India emblem.
  • CloudSEK publishes 'Tax Season, Open Season' documenting the campaign: forged ITD penalty-notice Office Memorandums delivered on WhatsApp as ITD.zip, with rotating archive sizes 2/34/35 MB observed.
  • Times of India and security press amplify the warning to ITR filers; follow-up reporting documents account-takeover and refund-diversion fraud variants and real victim losses during the season.

Sources cited for Tax-Themed Phishing and Malware Campaign Targeting Indian

More in phishing

Detection coverage for TL-2026-2654

As of 2026-09-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2654 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats