Skip to main content

Tax Season, Open Season: Phishing and Malware Campaigns Targeting Indian Taxpayers

0
Medium
Published: 07/30/2026 (07/30/2026, 10:18:37 UTC)
Source: AlienVault OTX General

Description

A sophisticated malware campaign is targeting Indian taxpayers during filing season by impersonating the Income Tax Department. Attackers distribute fake penalty notices via WhatsApp from unknown or compromised accounts, using forged Office Memorandums citing legitimate tax law sections and creating 72-hour deadlines to induce panic. The campaign delivers ITD.zip files containing malicious Android APKs and Windows executables that harvest OTPs, banking credentials, and enable remote access. The infrastructure relies on disposable domains using cheap TLDs and Alibaba Cloud storage for payload delivery. This activity is part of a broader ecosystem including refund SMS fraud, cloned e-Filing portals, and fake e-PAN emails. The operation demonstrates resource and planning through bilingual content, payload rotation to evade detection, and abuse of legitimate code-signing certificates.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/31/2026, 12:42:21 UTC

Technical Analysis

This campaign impersonates the Indian Income Tax Department during tax season, distributing fake penalty notices through WhatsApp from unknown or compromised accounts. The notices include forged Office Memorandums citing legitimate tax laws and impose 72-hour deadlines to pressure victims. The delivered payloads, packaged as ITD.zip files, contain malicious Android APKs and Windows executables that harvest one-time passwords (OTPs), banking credentials, and provide remote access capabilities. The attackers use disposable domains with inexpensive top-level domains and Alibaba Cloud storage for hosting payloads. The campaign is part of a broader fraud ecosystem involving refund SMS scams, cloned tax filing portals, and fake e-PAN emails. Techniques include bilingual messaging, frequent payload updates to avoid detection, and misuse of legitimate code-signing certificates, indicating significant planning and resources.

Potential Impact

Victims risk theft of banking credentials and OTPs, potentially leading to unauthorized financial transactions and account compromise. The malware enables remote access, increasing the risk of further system compromise and data exfiltration. The campaign's use of social engineering with fake official notices and time-sensitive threats increases the likelihood of victim compliance. The broader ecosystem of related frauds amplifies the overall risk to Indian taxpayers during tax season.

Defensive Guidance

No official patch or fix applies as this is a social engineering and malware distribution campaign. Defenders should educate users about this specific phishing tactic, emphasizing that the Income Tax Department does not send penalty notices via WhatsApp or impose 72-hour deadlines through such channels. Users should avoid opening unsolicited links or attachments from unknown or suspicious sources. Organizations can monitor for and block known disposable domains and Alibaba Cloud storage URLs used in this campaign. Employing mobile and endpoint security solutions capable of detecting malicious APKs and executables can help reduce risk. Since the campaign abuses legitimate code-signing certificates, reliance solely on code-signing for trust should be supplemented with behavioral detection. Patch status is not applicable; check vendor advisories for updates on detection capabilities.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.cloudsek.com/blog/tax-season-open-season-phishing-and-malware-campaigns-targeting-indian-taxpayers"]
Pulse Id
6a6b24fd9aca51b0320e47a6

Indicators of Compromise

Domain

ValueDescriptionCopy
domainlaoshunfa.xyz
domaingov-xnui.com
domaingova.lat
domainindiaaba.com
domainapeal.lol
domainaudet.club
domainbcgovtop.lol
domainckoming.study
domainclerk.lat
domainfsyahsxd.xin
domaingisudyawz.ink
domaingova.bar
domaingovj.one
domaingovtocki.shop
domainingovtop.click
domainkcsueaw.xin
domainkonimqh.study
domainlaiuatexqw.cc
domainlzaiwugsa.ink
domainoder.autos
domainqaksdiuw.xin
domainsfinmgov.club
domaintarif.lol
domaintzawccsw.xin
domainxcvgyuraw.live
domainzasudtytw.xin
domainzixhasda.xin
domainzuytyarws.xin
domainzxizusuy.xin
domainzytsyxbwa.live
domain22.laoshunfa.xyz

Hash

ValueDescriptionCopy
hash2d85a7a16d1eb86dfd92b00f6267733d
hash538ad8e0ad1fec0ecc54f9e120ac6ff9
hashdff2b7a23882445b4e354199bf38554f
hash7479fbc27320ae246db9030cca80809ec63de0e9
hash667b37eafb9ec5131ed4f017ed429a47dca3adf626b2fc85fc6424b1e17ff6e1

Url

ValueDescriptionCopy
urlhttp://gova.lat/1.html
urlhttp://govj.one/index.html

Threat ID: 6a6c856d9c2644c7f8ba4215

Added to database: 07/31/2026, 11:22:21 UTC

Last enriched: 07/31/2026, 12:42:21 UTC

Last updated: 09/14/2026, 13:24:36 UTC

Views: 118

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses