Indian Income Tax-Themed Phishing Campaign Targets Local Businesses
Essential information
- Published
- 22/12/2025 17:06
- Modified
- 23/12/2025 09:40
- Tags
- 2025-12-22 china-linked data harvesting income tax india nsis installer phishing rat remote access trojan
- Related entities
- 3 observables, 14 techniques (mitre), 1 malware, 3 others
Description
A sophisticated phishing campaign impersonating the Indian Income Tax Department has been targeting local businesses. The attack begins with a spear-phishing email containing a PDF attachment that directs victims to a fake compliance portal. This triggers the download of a malicious ZIP file, which initiates a multi-stage infection chain. The payload, delivered through NSIS installers, deploys a Remote Access Trojan (RAT) with persistence capabilities. The malware harvests system information and establishes communication with command and control servers. Technical indicators suggest a China-linked development environment. This campaign demonstrates how seemingly simple tax-themed phishing can lead to complete device compromise, emphasizing the need for heightened security awareness.