Indian Income Tax Department Phishing Lure Deploys Gh0st RAT and AsyncRAT Implants
ID: deab409f-8c81-52b2-b093-e35925b08e74
STIX ID: report--deab409f-8c81-52b2-b093-e35925b08e74
Feed Name: GBHackers
A targeted phishing campaign impersonating the Indian Income Tax Department uses fake government and Microsoft verification pages to deliver a digitally signed executable paired with a malicious DLL; the attack unfolds across six stages using signed-binary sideloading, a polyglot JPEG carrier, reflective in-memory loading, and session-aware injection to deploy two in-memory implants (a Gh0st RAT derivative and a Quasar/AsyncRAT-family .NET payload) with active C2s and multiple IOCs—raising the operational threat to high and recommending memory captures, network blocks, and monitoring for the MixedSvc service and named global events.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
