Cybercriminals Target Indian Taxpayers with Malware Phishing Campaign
Article Content
- •Cybercriminals are impersonating the Indian Income Tax Department in phishing attacks.
- •Victims are tricked into downloading malware through fake notices and urgent messaging.
- •The phishing campaign targets both individual taxpayers and businesses across India.
Cybercriminals are exploiting the tax season in India by launching phishing campaigns that impersonate the Income Tax Department. These campaigns utilize fake assessment notices and compliance warnings to deceive victims into downloading malware. The attackers have created convincing fake websites that closely resemble official government portals, employing urgent language to pressure individuals and businesses into action. The malware delivered can provide attackers with persistent access to compromised systems. The operation is currently active, targeting both individual taxpayers and businesses in India. No specific numbers of affected individuals or businesses have been reported, nor are there known CVEs associated with this campaign. The scope of the impact remains significant as the phishing attempts are widespread during the tax season. Security professionals are advised to remain vigilant against such tactics.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…