logo

Fake Income Tax Notices Used to Spread Malware

ID: 97a27b68-ec53-5c8d-b229-75f15f46dd13

STIX ID: report--97a27b68-ec53-5c8d-b229-75f15f46dd13

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Mayura Kathir

...
...

Mimecast Threat Research uncovered a targeted phishing campaign (active since October 2025) that impersonates the Indian Income Tax Department to coerce recipients into downloading malicious files from fake portals; the operation uses VBScript, NSIS droppers and password-protected ZIPs to deploy the XRed backdoor which supports credential theft, remote control, persistence via Registry Run keys and mutexes, USB worm-like spreading, and C2 exfiltration. The report lists compromised domains used for hosting fake portals, describes spear-phishing lures referencing Section 271(1)(c), and provides mitigation guidance including verification via official e-filing portals, email filtering, endpoint protection, and monitoring for suspicious outbound traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.