CYFIRMA reports a multi-domain campaign that impersonates the Indian Income Tax Department to lure victims into downloading a malicious VHDX file that delivers a loader and DLL payload. The operation uses ten disposable .shop domains, process injection into Runtimebroke.exe, and an attempted connection to xvcbvgfr.com, with infrastructure and artifacts tied to Common_Offline_Utility_ITR-1_to_4_AY2026-07-27.vhdx, Common_Offline_Utility_ITR-1_to_4_AY2026-27.exe, and tedutil.dll. #IncomeTaxDepartment #Runtimebroke.exe #tedutil.dll #xvcbvgfr.com
Keypoints
- The campaign abuses an Indian Income Tax Department Notice of Assessment theme to socially engineer victims.
- Ten fraudulent .shop domains were used to host a fake tax portal and distribute the malicious payload.
- The main delivery file is a VHDX disk image named Common_Offline_Utility_ITR-1_to_4_AY2026-07-27.vhdx.
- Inside the VHDX, a PE loader named Common_Offline_Utility_ITR-1_to_4_AY2026-27.exe loads the DLL payload tedutil.dll from its resource section.
- The malware performs process injection into Runtimebroke.exe and shows RAT-like capabilities such as persistence, host discovery, and remote communication.
- The campaign attempted network communication to xvcbvgfr.com resolving to 103.97.128.245, but no completed C2 session was observed.
- Observed tracking data showed 1,013 visit events and 48 download events, though these are not confirmed unique victims.
MITRE Techniques
- [T1204.002 ] User Execution: Malicious File – Victims are prompted to download and mount a malicious VHDX, relying on user interaction to trigger execution [‘Clicking this button initiates the download of a malicious VHDX file’]
- [T1055 ] Process Injection – The malware injects into Runtimebroke.exe to run inside a legitimate process and evade detection [‘process injection into Runtimebroke.exe’]
- [T1036 ] Masquerading – The payload and portal impersonate legitimate tax software and government communication to appear trusted [‘fraudulent Income Tax Department Notice of Assessment’; ‘mimics legitimate income-tax utility software’]
- [T1036.005 ] Masquerading: Match Legitimate Resource Name or Location – The executable uses misleading Microsoft-style metadata and a legitimate-sounding name to blend in [‘Original filename: topoedit.exe; File Description: Topology Editor; Product Name: Media Foundation Topology Editor’]
- [T1082 ] System Information Discovery – The report states the payload has discovery capabilities that can identify host/system details [‘capabilities related to persistence, system discovery, and remote command execution’]
- [T1071.001 ] Application Layer Protocol: Web Protocols – The malware attempted web-based network communication to its suspected endpoint over TCP/443 [‘attempted to connect to xvcbvgfr.com over TCP/443’]
Indicators of Compromise
- [Domains ] Fraudulent tax-themed portals used for delivery and tracking – zasxcd[.]shop, ssefcv[.]shop, and 8 more .shop domains
- [Domain ] Suspected C2 / network endpoint – xvcbvgfr[.]com
- [IP Address ] Resolved network endpoints associated with the campaign – 103[.]97[.]128[.]245, 103[.]59[.]103[.]170
- [File names ] Malicious disk image and loader delivered by the fake portal – Common_Offline_Utility_ITR-1_to_4_AY2026-07-27.vhdx, Common_Offline_Utility_ITR-1_to_4_AY2026-27.exe
- [DLL name ] Payload loaded from the loader’s resource section – tedutil.dll
- [SHA-256 hashes ] Identified sample hashes for campaign artifacts – 518ee4c9ae0321bd4fe8616e4f195f0079c6503109d2710e80e09d1a0f1dc98f, f4ae0f7c0c663e41dab28b2992f1afa9b97fe13a52f2d1fa26156554a23b99a7, and 71d15f3c13f5b11866cf65d9cf014236a47d221155ae992d9992abccedb66cf2
- [MD5 hashes ] Sample hashes for the VHDX, EXE, and DLL – 2462c9ca59a40ce04e3f072a95e104f0, e347d86749a1f9e61c6e3b330c681b50, and 69c5a70b15c886a7f9ab5449be286779
Read more: https://www.cyfirma.com/research/fake-tax-themed-phishing-campaign-delivers-malware/