CYFIRMA reported a tax-themed malware campaign using a fake Indian Income Tax Department portal on harivo[.]vip to trick victims into downloading Tax_Assessment_0609.zip and staged payloads Tax_Assessment.img, Tax_Assessment.exe, and libsvcs.dll. The malware uses ConfuserEx obfuscation, reflection-based DLL loading, persistence, and encrypted C2 traffic to support RAT-like control over Windows systems, with infrastructure tied to 103[.]231[.]12[.]27:4444. #Tax_Assessment.exe #libsvcs.dll #harivovip #IncomeTaxDepartment #XWorm
Keypoints
- The campaign impersonates the Indian Income Tax Department using a fake assessment notice hosted on harivo[.]vip.
- Victims are lured into downloading a malicious ZIP archive named Tax_Assessment_0609.zip.
- The infection chain uses a staged disk image, Tax_Assessment.img, which contains Tax_Assessment.exe and libsvcs.dll.
- Tax_Assessment.exe acts as a loader and uses Assembly.LoadFrom() and reflection to execute the DLL payload.
- Both binaries are protected with ConfuserEx and use stealth features such as hidden console windows, registry changes, and spoofed metadata.
- libsvcs.dll provides RAT-like functions including persistence, host discovery, user activity monitoring, remote execution, and encrypted C2 communication.
- Hardcoded infrastructure includes 103[.]231[.]12[.]27:4444, and the observed behavior resembles XWorm-like malware.
MITRE Techniques
- [T1566.002 ] Phishing: Spearphishing Link â The fake tax portal lures victims to download the malicious archive (âFraudulent Income Tax website â malicious archive downloadâ).
- [T1189 ] Drive-by Compromise â The fake portal delivers the ZIP archive through a deceptive website (âZIP archive with malware delivered via fake portalâ).
- [T1204.002 ] User Execution: Malicious File â The user is prompted to download and open the malicious file (âUser downloads/executes Tax_Assessment.exeâ).
- [T1218 ] System Binary Proxy Execution â The mounted disk image stages execution of the next components (âMounted disk image (Tax_Assessment.img) stages executionâ).
- [T1059 ] Command and Scripting Interpreter â The loader uses reflection-based .NET execution to run the payload (âReflection-based .NET dynamic executionâ).
- [T1620 ] Reflective Code Loading â Tax_Assessment.exe loads libsvcs.dll with Assembly.LoadFrom() (âAssembly.LoadFrom() loads libsvcs.dllâ).
- [T1027 ] Obfuscated/Compressed Files â ConfuserEx is used to hide the malicious code and complicate analysis (âConfuserEx obfuscation on EXE/DLLâ).
- [T1036 ] Masquerading â The files and portal impersonate tax documents and legitimate government communication (âDeceptive filenames/metadata impersonating tax docsâ).
- [T1036.005 ] Match Legitimate Resource Name or Location â The DLL uses fake Microsoft-like metadata to look trusted (âDLL metadata: âRuntime Service Hostâ, âMicrosoft Corporationââ).
- [T1140 ] Deobfuscate/Decode Files â The protected assemblies are unpacked/decoded at runtime (âRuntime decoding of protected assembliesâ).
- [T1564.003 ] Hide Artifacts: Hidden Window â The malware hides its console window during execution (âConsole window hidden during executionâ).
- [T1112 ] Modify Registry â The malware modifies registry settings for stealth and persistence (âRegistry mods for execution/persistenceâ).
- [T1547.001 ] Registry Run Keys / Startup Folder â The malware uses startup registration and auto-run behavior (âSetAutoRun, AddToStartupAdmin/NonAdminâ).
- [T1053.005 ] Scheduled Task â Scheduled-task persistence is included in the malwareâs capabilities (âScheduled-task persistence functionalityâ).
- [T1082 ] System Information Discovery â The payload gathers OS and host information (âGetWindowsVersion() collects OS/host detailsâ).
- [T1518.001 ] Security Software Discovery â The malware checks for security products (âGetSecurityInfo() enumerates security productsâ).
- [T1033 ] System Owner/User Discovery â The payload collects user information (âUser info collection during reconnaissanceâ).
- [T1497.001 ] Virtualization/Sandbox Evasion â The malware performs anti-analysis checks before execution (âAnti-analysis checks before executionâ).
- [T1071.001 ] Application Layer Protocol: Web Protocols â The C2 communication uses application-layer web communications (âC2 via application-layer web communicationsâ).
- [T1573 ] Encrypted Channel â The malware uses an embedded 32-byte key for encrypted C2 (â32-byte embedded encryption key for C2â˛).
- [T1105 ] Ingress Tool Transfer â Additional payload loading/execution is supported by the malware (âDynamic payload loading/executionâ).
- [T1219 ] Remote Access Software â The payload provides RAT-style remote access and command execution (âRAT functionality for remote access/command executionâ).
Indicators of Compromise
- [Domain ] fraudulent tax portal and campaign hosting â harivo[.]vip, harivo.vip
- [IP address ] hardcoded C2 server and malicious infrastructure â 103[.]231[.]12[.]27, 38[.]76[.]161[.]218
- [File names ] staged infection-chain files â Tax_Assessment_0609.zip, Tax_Assessment.img, Tax_Assessment.exe, libsvcs.dll
- [MD5 hashes ] sample file hashes from the campaign â 3adcf5fca3f4fe23a9b73951e20d43bc, ba036fbf209b2dbdfec3fd3dee9b1798, and 2 more hashes
- [SHA-256 hashes ] YARA and IOC hashes associated with the campaign â 372d7d8ca222e03afa5970848cf88efa6a3bc5146d20398601285fc7eaea6735, f5dc1016679f54f2be22da0ff6642046f7a943410c188514b96c28d8a3b95e12, and 2 more hashes
- [Port ] encrypted C2 communication endpoint â 103[.]231[.]12[.]27:4444
- [Strings ] campaign-specific lure text used on the fake portal â Download Assessment Order & Workings, NOTICE OF ASSESSMENT