Watch out — that income tax form could actually be dangerous malware

https://cdn.mos.cms.futurecdn.net/AAnrrKYFEkWSGnT672jgVH-1920-80.jpg
  • Fake tax notices are becoming delivery vehicles for sophisticated remote access malware
  • Attackers hide malicious code behind convincing government branding and legal references
  • The malware quietly establishes encrypted communication with servers outside the country

A new phishing campaign is using fake income tax assessment notices to deliver dangerous malware to unsuspecting victims across India.

Researchers at CYFIRMA identified the operation, which relies on a fraudulent website built to resemble official communication from the Indian Income Tax Department closely.

The fake portal, hosted on a recently registered domain, presents a convincing assessment order complete with legal references, financial penalties, and urgent compliance language designed to pressure recipients into acting quickly.

How the infection unfolds

Victims who interact with the fake notice are prompted to download a ZIP archive disguised as official assessment documentation and supporting calculations.

Once extracted, that archive reveals a disk image file functioning as a container for the...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more