logo

Hackers Abuse Indian Tax Notice Lures to Deliver PE Loader and libsvcs.dll Payload

ID: 9c9fdd98-c0df-51af-9483-eb462989e754

STIX ID: report--9c9fdd98-c0df-51af-9483-eb462989e754

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

Author: Mayura Kathir

...
...

A targeted malware campaign impersonating the Indian Income Tax Department used a fake portal (harivo.vip) and a malicious ZIP containing an IMG with Tax_Assessment.exe and libsvcs.dll to deploy a ConfuserEx-obfuscated RAT that implements persistence, host discovery, user monitoring, and encrypted C2 communications (hardcoded 103.231.12.27:4444); the report provides file and image hashes, domain/IP IOCs, analysis of reflection-based DLL loading, and recommended detection/mitigation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.