Tax Season, Open Season: Phishing and Malware Campaigns Targeting Indian Taxpayers
A sophisticated malware campaign is targeting Indian taxpayers during filing season by impersonating the Income Tax Department. Attackers distribute fake penalty notices via WhatsApp from unknown or compromised accounts, using forged Office Memorandums citing legitimate tax law sections and creating 72-hour deadlines to induce panic. The campaign delivers ITD.zip files containing malicious Android APKs and Windows executables that harvest OTPs, banking credentials, and enable remote access. The infrastructure relies on disposable domains using cheap TLDs and Alibaba Cloud storage for payload delivery. This activity is part of a broader ecosystem including refund SMS fraud, cloned e-Filing portals, and fake e-PAN emails. The operation demonstrates resource and planning through bilingual content, payload rotation to evade detection, and abuse of legitimate code-signing certificates.
AI Analysis
Technical Summary
This campaign impersonates the Indian Income Tax Department during tax season, distributing fake penalty notices through WhatsApp from unknown or compromised accounts. The notices include forged Office Memorandums citing legitimate tax laws and impose 72-hour deadlines to pressure victims. The delivered payloads, packaged as ITD.zip files, contain malicious Android APKs and Windows executables that harvest one-time passwords (OTPs), banking credentials, and provide remote access capabilities. The attackers use disposable domains with inexpensive top-level domains and Alibaba Cloud storage for hosting payloads. The campaign is part of a broader fraud ecosystem involving refund SMS scams, cloned tax filing portals, and fake e-PAN emails. Techniques include bilingual messaging, frequent payload updates to avoid detection, and misuse of legitimate code-signing certificates, indicating significant planning and resources.
Potential Impact
Victims risk theft of banking credentials and OTPs, potentially leading to unauthorized financial transactions and account compromise. The malware enables remote access, increasing the risk of further system compromise and data exfiltration. The campaign's use of social engineering with fake official notices and time-sensitive threats increases the likelihood of victim compliance. The broader ecosystem of related frauds amplifies the overall risk to Indian taxpayers during tax season.
Mitigation Recommendations
No official patch or fix applies as this is a social engineering and malware distribution campaign. Defenders should educate users about this specific phishing tactic, emphasizing that the Income Tax Department does not send penalty notices via WhatsApp or impose 72-hour deadlines through such channels. Users should avoid opening unsolicited links or attachments from unknown or suspicious sources. Organizations can monitor for and block known disposable domains and Alibaba Cloud storage URLs used in this campaign. Employing mobile and endpoint security solutions capable of detecting malicious APKs and executables can help reduce risk. Since the campaign abuses legitimate code-signing certificates, reliance solely on code-signing for trust should be supplemented with behavioral detection. Patch status is not applicable; check vendor advisories for updates on detection capabilities.
Affected Countries
India
Indicators of Compromise
- domain: laoshunfa.xyz
- domain: gov-xnui.com
- domain: gova.lat
- domain: indiaaba.com
- hash: 2d85a7a16d1eb86dfd92b00f6267733d
- hash: 538ad8e0ad1fec0ecc54f9e120ac6ff9
- hash: dff2b7a23882445b4e354199bf38554f
- hash: 7479fbc27320ae246db9030cca80809ec63de0e9
- hash: 667b37eafb9ec5131ed4f017ed429a47dca3adf626b2fc85fc6424b1e17ff6e1
- url: http://gova.lat/1.html
- url: http://govj.one/index.html
- domain: apeal.lol
- domain: audet.club
- domain: bcgovtop.lol
- domain: ckoming.study
- domain: clerk.lat
- domain: fsyahsxd.xin
- domain: gisudyawz.ink
- domain: gova.bar
- domain: govj.one
- domain: govtocki.shop
- domain: ingovtop.click
- domain: kcsueaw.xin
- domain: konimqh.study
- domain: laiuatexqw.cc
- domain: lzaiwugsa.ink
- domain: oder.autos
- domain: qaksdiuw.xin
- domain: sfinmgov.club
- domain: tarif.lol
- domain: tzawccsw.xin
- domain: xcvgyuraw.live
- domain: zasudtytw.xin
- domain: zixhasda.xin
- domain: zuytyarws.xin
- domain: zxizusuy.xin
- domain: zytsyxbwa.live
- domain: 22.laoshunfa.xyz
Tax Season, Open Season: Phishing and Malware Campaigns Targeting Indian Taxpayers
Description
A sophisticated malware campaign is targeting Indian taxpayers during filing season by impersonating the Income Tax Department. Attackers distribute fake penalty notices via WhatsApp from unknown or compromised accounts, using forged Office Memorandums citing legitimate tax law sections and creating 72-hour deadlines to induce panic. The campaign delivers ITD.zip files containing malicious Android APKs and Windows executables that harvest OTPs, banking credentials, and enable remote access. The infrastructure relies on disposable domains using cheap TLDs and Alibaba Cloud storage for payload delivery. This activity is part of a broader ecosystem including refund SMS fraud, cloned e-Filing portals, and fake e-PAN emails. The operation demonstrates resource and planning through bilingual content, payload rotation to evade detection, and abuse of legitimate code-signing certificates.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign impersonates the Indian Income Tax Department during tax season, distributing fake penalty notices through WhatsApp from unknown or compromised accounts. The notices include forged Office Memorandums citing legitimate tax laws and impose 72-hour deadlines to pressure victims. The delivered payloads, packaged as ITD.zip files, contain malicious Android APKs and Windows executables that harvest one-time passwords (OTPs), banking credentials, and provide remote access capabilities. The attackers use disposable domains with inexpensive top-level domains and Alibaba Cloud storage for hosting payloads. The campaign is part of a broader fraud ecosystem involving refund SMS scams, cloned tax filing portals, and fake e-PAN emails. Techniques include bilingual messaging, frequent payload updates to avoid detection, and misuse of legitimate code-signing certificates, indicating significant planning and resources.
Potential Impact
Victims risk theft of banking credentials and OTPs, potentially leading to unauthorized financial transactions and account compromise. The malware enables remote access, increasing the risk of further system compromise and data exfiltration. The campaign's use of social engineering with fake official notices and time-sensitive threats increases the likelihood of victim compliance. The broader ecosystem of related frauds amplifies the overall risk to Indian taxpayers during tax season.
Defensive Guidance
No official patch or fix applies as this is a social engineering and malware distribution campaign. Defenders should educate users about this specific phishing tactic, emphasizing that the Income Tax Department does not send penalty notices via WhatsApp or impose 72-hour deadlines through such channels. Users should avoid opening unsolicited links or attachments from unknown or suspicious sources. Organizations can monitor for and block known disposable domains and Alibaba Cloud storage URLs used in this campaign. Employing mobile and endpoint security solutions capable of detecting malicious APKs and executables can help reduce risk. Since the campaign abuses legitimate code-signing certificates, reliance solely on code-signing for trust should be supplemented with behavioral detection. Patch status is not applicable; check vendor advisories for updates on detection capabilities.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.cloudsek.com/blog/tax-season-open-season-phishing-and-malware-campaigns-targeting-indian-taxpayers"]
- Pulse Id
- 6a6b24fd9aca51b0320e47a6
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainlaoshunfa.xyz | — | |
domaingov-xnui.com | — | |
domaingova.lat | — | |
domainindiaaba.com | — | |
domainapeal.lol | — | |
domainaudet.club | — | |
domainbcgovtop.lol | — | |
domainckoming.study | — | |
domainclerk.lat | — | |
domainfsyahsxd.xin | — | |
domaingisudyawz.ink | — | |
domaingova.bar | — | |
domaingovj.one | — | |
domaingovtocki.shop | — | |
domainingovtop.click | — | |
domainkcsueaw.xin | — | |
domainkonimqh.study | — | |
domainlaiuatexqw.cc | — | |
domainlzaiwugsa.ink | — | |
domainoder.autos | — | |
domainqaksdiuw.xin | — | |
domainsfinmgov.club | — | |
domaintarif.lol | — | |
domaintzawccsw.xin | — | |
domainxcvgyuraw.live | — | |
domainzasudtytw.xin | — | |
domainzixhasda.xin | — | |
domainzuytyarws.xin | — | |
domainzxizusuy.xin | — | |
domainzytsyxbwa.live | — | |
domain22.laoshunfa.xyz | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash2d85a7a16d1eb86dfd92b00f6267733d | — | |
hash538ad8e0ad1fec0ecc54f9e120ac6ff9 | — | |
hashdff2b7a23882445b4e354199bf38554f | — | |
hash7479fbc27320ae246db9030cca80809ec63de0e9 | — | |
hash667b37eafb9ec5131ed4f017ed429a47dca3adf626b2fc85fc6424b1e17ff6e1 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://gova.lat/1.html | — | |
urlhttp://govj.one/index.html | — |
Threat ID: 6a6c856d9c2644c7f8ba4215
Added to database: 07/31/2026, 11:22:21 UTC
Last enriched: 07/31/2026, 12:42:21 UTC
Last updated: 09/14/2026, 13:24:36 UTC
Views: 118
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.