Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Indian Income Tax-Themed Attacking Businesses with a Multi-Stage Infection Chain

## Cybersecurity: Phishing Campaign Targeting Indian Businesses

Cybersecurity: Phishing Campaign Targeting Indian Businesses

Cybercriminals have increasingly exploited the Income Tax Return (ITR) filing season to launch sophisticated phishing campaigns directed at Indian businesses. By leveraging public anxiety regarding tax compliance and refund timelines, attackers have crafted deceptive schemes that mimic official government communications.

The latest attacks employ a multi-stage infection chain, beginning with a spear-phishing email and culminating in the deployment of persistent malware capable of full system compromise.

The attack initiates with an email subject tagged "Tax Compliance Review Notice," allegedly from the Income Tax Department. Close examination reveals the sender uses a suspicious Outlook[.]com address rather than an official government domain. The email body lacks text, featuring only an embedded image indistinguishable from a genuine notice, bypassing standard text-based spam filters. This tactic creates a false sense of urgency by citing fabricated deadlines and compliance issues.

The attack initiates with an email subject tagged "Tax Compliance Review Notice," allegedly from the Income Tax Department.
Charles Nolan · Thehackingpost

Recipients are prompted to open an attachment named "Review Annexure.pdf," resembling a legitimate tax document. This PDF includes a malicious link directing users to a fraudulent compliance portal. Seqrite analysts identified that the portal triggers the download of a ZIP archive while instructing users to disable their antivirus software under the guise of "compatibility issues."

The campaign's technical sophistication emerges when victims engage with the downloaded payload. The infection process uses a two-stage NSIS installer that unpacks multiple files to establish a foothold on the victim's machine. The malware installs a persistent service named NSecRTS.exe to ensure it runs automatically in the background. This service communicates with Command and Control (C2) servers over non-standard ports, such as 48991 and 48992.

Advertisement

Researchers noted that technical indicators, including Simplified Chinese language usage and specific code-signing certificates, suggest the tooling originated from a China-linked development environment. This transformation from a simple phishing email to a fully operational Remote Access Trojan (RAT) underscores the critical need for vigilance against multi-stage threats.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories