Indian Income Tax-Themed Phishing Campaign Targets Local Businesses
A sophisticated phishing campaign impersonating the Indian Income Tax Department has been targeting local businesses. The attack begins with a spear-phishing email containing a PDF attachment that directs victims to a fake compliance portal. This triggers the download of a malicious ZIP file, which initiates a multi-stage infection chain. The payload, delivered through NSIS installers, deploys a Remote Access Trojan (RAT) with persistence capabilities. The malware harvests system information and establishes communication with command and control servers. Technical indicators suggest a China-linked development environment. This campaign demonstrates how seemingly simple tax-themed phishing can lead to complete device compromise, emphasizing the need for heightened security awareness.
Pulse ID: 69497ab3f381b44007add888
Pulse Link: https://otx.alienvault.com/pulse/69497ab3f381b44007add888
Pulse Author: AlienVault
Created: 2025-12-22 17:06:59
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#China #CyberSecurity #Email #India #InfoSec #Malware #OTX #OpenThreatExchange #PDF #Phishing #RAT #RemoteAccessTrojan #SpearPhishing #Trojan #ZIP #bot #AlienVault







