logo

Indian Income Tax Department Phishing Lure Deploys Gh0st RAT and AsyncRAT Implants

ID: deab409f-8c81-52b2-b093-e35925b08e74

STIX ID: report--deab409f-8c81-52b2-b093-e35925b08e74

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-07-08

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

A targeted phishing campaign impersonating the Indian Income Tax Department uses fake government and Microsoft verification pages to deliver a digitally signed executable paired with a malicious DLL; the attack unfolds across six stages using signed-binary sideloading, a polyglot JPEG carrier, reflective in-memory loading, and session-aware injection to deploy two in-memory implants (a Gh0st RAT derivative and a Quasar/AsyncRAT-family .NET payload) with active C2s and multiple IOCs—raising the operational threat to high and recommending memory captures, network blocks, and monitoring for the MixedSvc service and named global events.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.