Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Tax Season, Open Season: Phishing and Malware Campaigns Targeting Indian Taxpayers

0
Medium
Published: 07/30/2026 (07/30/2026, 10:18:37 UTC)
Source: AlienVault OTX General

Description

A sophisticated malware campaign is targeting Indian taxpayers during filing season by impersonating the Income Tax Department. Attackers distribute fake penalty notices via WhatsApp from unknown or compromised accounts, using forged Office Memorandums citing legitimate tax law sections and creating 72-hour deadlines to induce panic. The campaign delivers ITD.zip files containing malicious Android APKs and Windows executables that harvest OTPs, banking credentials, and enable remote access. The infrastructure relies on disposable domains using cheap TLDs and Alibaba Cloud storage for payload delivery. This activity is part of a broader ecosystem including refund SMS fraud, cloned e-Filing portals, and fake e-PAN emails. The operation demonstrates resource and planning through bilingual content, payload rotation to evade detection, and abuse of legitimate code-signing certificates.

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.cloudsek.com/blog/tax-season-open-season-phishing-and-malware-campaigns-targeting-indian-taxpayers"]
Adversary
null
Pulse Id
6a6b24fd9aca51b0320e47a6
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainlaoshunfa.xyz
domaingov-xnui.com
domaingova.lat
domainindiaaba.com
domainapeal.lol
domainaudet.club
domainbcgovtop.lol
domainckoming.study
domainclerk.lat
domainfsyahsxd.xin
domaingisudyawz.ink
domaingova.bar
domaingovj.one
domaingovtocki.shop
domainingovtop.click
domainkcsueaw.xin
domainkonimqh.study
domainlaiuatexqw.cc
domainlzaiwugsa.ink
domainoder.autos
domainqaksdiuw.xin
domainsfinmgov.club
domaintarif.lol
domaintzawccsw.xin
domainxcvgyuraw.live
domainzasudtytw.xin
domainzixhasda.xin
domainzuytyarws.xin
domainzxizusuy.xin
domainzytsyxbwa.live
domain22.laoshunfa.xyz

Hash

ValueDescriptionCopy
hash2d85a7a16d1eb86dfd92b00f6267733d
hash538ad8e0ad1fec0ecc54f9e120ac6ff9
hashdff2b7a23882445b4e354199bf38554f
hash7479fbc27320ae246db9030cca80809ec63de0e9
hash667b37eafb9ec5131ed4f017ed429a47dca3adf626b2fc85fc6424b1e17ff6e1

Url

ValueDescriptionCopy
urlhttp://gova.lat/1.html
urlhttp://govj.one/index.html

Threat ID: 6a6c856d9c2644c7f8ba4215

Added to database: 07/31/2026, 11:22:21 UTC

Last updated: 07/31/2026, 11:23:28 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses