Tax Season, Open Season: Phishing and Malware Campaigns Targeting Indian Taxpayers

Tax Season, Open Season: Phishing and Malware Campaigns Targeting Indian Taxpayers
Attackers are spreading fake Income Tax Department penalty notices and refund lures through WhatsApp, SMS, email, and lookalike websites to trick taxpayers into opening malicious files or entering credentials. The campaigns deliver malware such as ITD_Tax_Notice.exe and use disposable domains, fake Office Memorandums, and cloud-hosted second-stage payloads to steal data and enable remote access. #IncomeTaxDepartment #ITD_Tax_Notice.exe #ipwho.is #AlibabaCloud

Keypoints

  • Fake tax notices are being sent through WhatsApp and other chat apps using unknown or compromised accounts.
  • The lure typically uses a bilingual forged Office Memorandum with Government of India branding, fake legal citations, and a 72-hour deadline.
  • The “Download Documents” button in the phishing flow delivers malicious files, including ITD.zip and the Windows executable ITD_Tax_Notice.exe.
  • Observed archive sizes vary between 2 MB, 34 MB, and 35 MB, suggesting payload rotation to evade detection.
  • Lookalike tax sites are hosted on disposable domains using low-trust TLDs such as .lol, .xin, .ink, .autos, and similar namespaces.
  • The Windows payload masquerades as svchost.exe, is packed and signed with an EV certificate, and fetches a second-stage binary from Alibaba Cloud storage.
  • The broader ecosystem also includes fake refund messages, cloned e-Filing portals, fake e-PAN emails, and fraudulent tax consultants or refund agents.

MITRE Techniques

  • [T1486] Data Encrypted for Impact – Mentioned in the context of malicious archive and payload delivery used to drop malware from ZIP files (‘The attachment is presented as ITD.zip, but the payload is a malicious Android application (APK).’).
  • [T1497] Virtualization/Sandbox Evasion – The payload checks for analysis environments and changes sleep behavior to avoid detonation (‘The sandbox recorded modified sleep behaviour and virtualisation/sandbox checks’).
  • [T1574.002] DLL Side-Loading – The campaign is described as chaining archives or disk images to signed-binary sideloading to load the payload (‘Campaigns … have chained an archive or disk image to a signed-binary sideload’).
  • [T1055] Process Injection – The report states the malware can load the second stage directly into memory and is associated with process-injection-style behavior (‘loaded a remote access trojan or an infostealer into memory’).
  • [T1012] Query Registry – The sample performs registry reconnaissance during execution (‘The sandbox recorded … registry … reconnaissance’).
  • [T1518.001] Security Software Discovery – The malware checks for security products as part of its evasion and reconnaissance (‘The sandbox recorded … security-software … reconnaissance’).
  • [T1016] System Network Configuration Discovery – The payload gathers network configuration details (‘The sandbox recorded … system-information reconnaissance’).
  • [T1082] System Information Discovery – The payload fingerprints the victim and collects system data (‘It fingerprints the machine … and then pull[s] the real malware’).
  • [T1105] Ingress Tool Transfer – The malware downloads a follow-on binary from cloud storage (‘it reaches an Alibaba Cloud storage bucket … to fetch a follow-on payload’).
  • [T1071] Application Layer Protocol – The campaign uses web-based delivery and HTTP(S) retrieval for the second stage (‘It queries the legitimate geolocation service ipwho[.]is’).
  • [T1095] Non-Application Layer Protocol – The report notes network use beyond normal app-layer communication in the staging chain (‘Only two network endpoints were observed’).
  • [T1573] Encrypted Channel – The second-stage download is served over HTTPS (‘hxxps://vss2.oss-cn-hongkong[.]aliyuncs[.]com/88.bin’).

Indicators of Compromise

  • [Domains ] Fake notice and payload infrastructure – apeal[.]lol, tarif[.]lol, gov-xnui[.]com and other disposable lookalike domains
  • [Filename ] Malicious archive / Windows payload – ITD.zip, ITD_Tax_Notice.exe
  • [File hashes ] Windows executable identifiers – MD5 dff2b7a23882445b4e354199bf38554f, SHA-256 667b37eafb9ec5131ed4f017ed429a47dca3adf626b2fc85fc6424b1e17ff6e1, and other 2 hashes
  • [IP address ] Abused cloud staging host – 47.79.66.58
  • [URL ] Second-stage download location – hxxps://vss2.oss-cn-hongkong[.]aliyuncs[.]com/88.bin
  • [Certificate details ] Signing chain / signer clues – Certum Extended Validation Code Signing 2021 CA, serial 2D85A7A16D1EB86DFD92B00F6267733D


Read more: https://www.cloudsek.com/blog/tax-season-open-season-phishing-and-malware-campaigns-targeting-indian-taxpayers