216.73.217.22

Indian Income Tax-Themed Phishing Campaign Targets Local Businesses

· Published 22/12/2025 17:06 · Modified 23/12/2025 09:40

Export JSON

Essential information

Published
22/12/2025 17:06
Modified
23/12/2025 09:40
Tags
2025-12-22 china-linked data harvesting income tax india nsis installer phishing rat remote access trojan
Related entities
3 observables, 14 techniques (mitre), 1 malware, 3 others

Description

A sophisticated campaign impersonating the Indian Department has been targeting local businesses. The attack begins with a spear- email containing a PDF attachment that directs victims to a fake compliance portal. This triggers the download of a malicious ZIP file, which initiates a multi-stage infection chain. The payload, delivered through NSIS installers, deploys a () with persistence capabilities. The malware harvests system information and establishes communication with command and control servers. Technical indicators suggest a development environment. This campaign demonstrates how seemingly simple tax-themed can lead to complete device compromise, emphasizing the need for heightened security awareness.

External references