
A China-linked phishing and malware campaign is impersonating the Income Tax Department and the Ministry of Finance to trick taxpayers into installing malicious software on their computers, a cybersecurity probe has revealed.
The phishing campaign, uncovered by cybersecurity and counter-threat intelligence firm Shreshta IT Technologies Pvt Ltd, appears to be timed with the assessment year 2026-27 income tax filing season, when taxpayers and businesses are more likely to trust official-looking emails on tax notices, compliance requirements and penalties.
According to Shreshta, victims receive an official-looking bilingual (Hindi-English) “office memorandum”, alleging a tax irregularity and directing them to submit documents within 72 hours or face legal action. The attached file, however, installs malware that silently compromises the victim’s computer and gives attackers remote access.
The threat research team at Shreshta traced the operation to a network of 379 lookalike domains hosted across providers in China and Hong Kong. The researchers cited multiple indicators pointing to a China-based operator, including Chinese-language artefacts embedded in phishing pages and the use of OFD — a document format widely used in China — as part of the lure.
“This is a well-resourced operation that weaponises trust in a govt institution at exactly the moment people expect to hear from the tax department,” Shreshta CEO Swapneel Patnekar told TOI.
“The emails look official, create panic with a 72-hour deadline, and the document they ask you to open is malware. The single most important thing to remember is that the Income Tax Department does not send penalty notices from Gmail or Outlook addresses,” he further said.
Shreshta advised taxpayers and businesses to treat any tax-related email demanding immediate action as suspicious. Recipients should verify communications by logging into the official Income Tax portal (incometax.gov.in), he said, adding that users must not open .exe files or compressed folders containing programs that are commonly used to deliver malware.
“Most of these cyber fraud emails originate from servers based in China or Hong Kong. During our investigation, we identified 18 suspicious IP addresses, of which 11 were linked to Alibaba and other Chinese cloud service providers. The fraudsters are primarily targeting urban residents as the common sense that the majority of urbanites pay income tax. Their modus operandi involves sending emails that create panic by mentioning fines, penalties or urgent action. Once the recipient downloads the attachment and follows the instructions, malware gets installed on the device. The system may freeze for a few seconds, during which sensitive data can be compromised. We thank Shreshta IT Technologies Pvt. Ltd for alerting the govt and sensitising people about this,” said Shivaling, programme director of Excellence for Cybersecurity (CySeck), Bengaluru.
Source from: https://timesofindia.indiatimes.com/city/hubballi/china-linked-phishing-scam-impersonates-i-t-dept-probe-reveals/articleshowprint/132578515.cms


