Tax Season, Open Season: Phishing and Malware Campaigns Targeting Indian Taxpayers
A sophisticated malware campaign is targeting Indian taxpayers during filing season by impersonating the Income Tax Department. Attackers distribute fake penalty notices via WhatsApp from unknown or compromised accounts, using forged Office Memorandums citing legitimate tax law sections and creating 72-hour deadlines to induce panic. The campaign delivers ITD.zip files containing malicious Android APKs and Windows executables that harvest OTPs, banking credentials, and enable remote access. The infrastructure relies on disposable domains using cheap TLDs and Alibaba Cloud storage for payload delivery. This activity is part of a broader ecosystem including refund SMS fraud, cloned e-Filing portals, and fake e-PAN emails. The operation demonstrates resource and planning through bilingual content, payload rotation to evade detection, and abuse of legitimate code-signing certificates.
Indicators of Compromise
- domain: laoshunfa.xyz
- domain: gov-xnui.com
- domain: gova.lat
- domain: indiaaba.com
- hash: 2d85a7a16d1eb86dfd92b00f6267733d
- hash: 538ad8e0ad1fec0ecc54f9e120ac6ff9
- hash: dff2b7a23882445b4e354199bf38554f
- hash: 7479fbc27320ae246db9030cca80809ec63de0e9
- hash: 667b37eafb9ec5131ed4f017ed429a47dca3adf626b2fc85fc6424b1e17ff6e1
- url: http://gova.lat/1.html
- url: http://govj.one/index.html
- domain: apeal.lol
- domain: audet.club
- domain: bcgovtop.lol
- domain: ckoming.study
- domain: clerk.lat
- domain: fsyahsxd.xin
- domain: gisudyawz.ink
- domain: gova.bar
- domain: govj.one
- domain: govtocki.shop
- domain: ingovtop.click
- domain: kcsueaw.xin
- domain: konimqh.study
- domain: laiuatexqw.cc
- domain: lzaiwugsa.ink
- domain: oder.autos
- domain: qaksdiuw.xin
- domain: sfinmgov.club
- domain: tarif.lol
- domain: tzawccsw.xin
- domain: xcvgyuraw.live
- domain: zasudtytw.xin
- domain: zixhasda.xin
- domain: zuytyarws.xin
- domain: zxizusuy.xin
- domain: zytsyxbwa.live
- domain: 22.laoshunfa.xyz
Tax Season, Open Season: Phishing and Malware Campaigns Targeting Indian Taxpayers
Description
A sophisticated malware campaign is targeting Indian taxpayers during filing season by impersonating the Income Tax Department. Attackers distribute fake penalty notices via WhatsApp from unknown or compromised accounts, using forged Office Memorandums citing legitimate tax law sections and creating 72-hour deadlines to induce panic. The campaign delivers ITD.zip files containing malicious Android APKs and Windows executables that harvest OTPs, banking credentials, and enable remote access. The infrastructure relies on disposable domains using cheap TLDs and Alibaba Cloud storage for payload delivery. This activity is part of a broader ecosystem including refund SMS fraud, cloned e-Filing portals, and fake e-PAN emails. The operation demonstrates resource and planning through bilingual content, payload rotation to evade detection, and abuse of legitimate code-signing certificates.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.cloudsek.com/blog/tax-season-open-season-phishing-and-malware-campaigns-targeting-indian-taxpayers"]
- Adversary
- null
- Pulse Id
- 6a6b24fd9aca51b0320e47a6
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainlaoshunfa.xyz | — | |
domaingov-xnui.com | — | |
domaingova.lat | — | |
domainindiaaba.com | — | |
domainapeal.lol | — | |
domainaudet.club | — | |
domainbcgovtop.lol | — | |
domainckoming.study | — | |
domainclerk.lat | — | |
domainfsyahsxd.xin | — | |
domaingisudyawz.ink | — | |
domaingova.bar | — | |
domaingovj.one | — | |
domaingovtocki.shop | — | |
domainingovtop.click | — | |
domainkcsueaw.xin | — | |
domainkonimqh.study | — | |
domainlaiuatexqw.cc | — | |
domainlzaiwugsa.ink | — | |
domainoder.autos | — | |
domainqaksdiuw.xin | — | |
domainsfinmgov.club | — | |
domaintarif.lol | — | |
domaintzawccsw.xin | — | |
domainxcvgyuraw.live | — | |
domainzasudtytw.xin | — | |
domainzixhasda.xin | — | |
domainzuytyarws.xin | — | |
domainzxizusuy.xin | — | |
domainzytsyxbwa.live | — | |
domain22.laoshunfa.xyz | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash2d85a7a16d1eb86dfd92b00f6267733d | — | |
hash538ad8e0ad1fec0ecc54f9e120ac6ff9 | — | |
hashdff2b7a23882445b4e354199bf38554f | — | |
hash7479fbc27320ae246db9030cca80809ec63de0e9 | — | |
hash667b37eafb9ec5131ed4f017ed429a47dca3adf626b2fc85fc6424b1e17ff6e1 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://gova.lat/1.html | — | |
urlhttp://govj.one/index.html | — |
Threat ID: 6a6c856d9c2644c7f8ba4215
Added to database: 07/31/2026, 11:22:21 UTC
Last updated: 07/31/2026, 11:23:28 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.