Hackers Use Fake Income Tax Assessment Pages to Infect Windows Systems
ID: 3f0c3cfa-d677-5124-9c68-7ac2a1fbfca2
STIX ID: report--3f0c3cfa-d677-5124-9c68-7ac2a1fbfca2
Feed Name: cybersecurityNews.com
**TAX#TRIDENT** is an active multi‑chain malware campaign targeting Windows users in India that lures victims with fake Indian Income Tax assessment pages; it delivers signed remote management clients (ClientSetup) and a hijacked ManageEngine UEMS agent to obtain persistent remote access. The report describes three infection chains (ZIP-delivered signed executable, VBScript downloader, and a chain that installs a legitimate ManageEngine agent pointed to an attacker server), supplies extensive IoCs (domains, IPs, filenames, SHA256, directories, services, drivers, ports), and recommends behavioral detections such as monitoring svchost.exe from nonstandard paths, UAC policy changes, file engines executing web‑style extensions, and network indicators on ports 6671/6681/6683 and 8383/8027.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
