Hackers Abuse Indian Tax Notice Lures to Deliver PE Loader and libsvcs.dll Payload
ID: 9c9fdd98-c0df-51af-9483-eb462989e754
STIX ID: report--9c9fdd98-c0df-51af-9483-eb462989e754
Feed Name: GBHackers
A targeted malware campaign impersonating the Indian Income Tax Department used a fake portal (harivo.vip) and a malicious ZIP containing an IMG with Tax_Assessment.exe and libsvcs.dll to deploy a ConfuserEx-obfuscated RAT that implements persistence, host discovery, user monitoring, and encrypted C2 communications (hardcoded 103.231.12.27:4444); the report provides file and image hashes, domain/IP IOCs, analysis of reflection-based DLL loading, and recommended detection/mitigation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
