Fake Tax Assessment Pages Infect Windows Users with Malware
Article Content
Browse articles
- •The TAX#TRIDENT campaign targets Windows users in India with fake tax documents.
- •Malicious files are disguised as official income tax assessments to trick victims.
- •The attack leverages urgency to increase the likelihood of user interaction.
Hackers are targeting Windows users in India with a campaign named TAX#TRIDENT, utilizing fake income tax assessment pages to distribute malware. Victims are lured into downloading malicious ZIP files disguised as official documents, creating a sense of urgency around tax penalties. The campaign has shown versatility in delivery methods while maintaining the same deceptive tax lure. Currently, there are no specific CVEs or tools mentioned, but the attack is ongoing and poses a significant risk to users who may fall for these scams. Security researchers are monitoring the situation closely, but specific numbers on affected users or systems have not been disclosed.
Ask AI about this cluster
Answers cite the sources they use
Updated 124d ago How this analysis works
Timeline
2026-05-20
TAX#TRIDENT campaign identified
Researchers confirmed the ongoing campaign targeting Windows users in India with fake tax assessment pages.
Gbhackers2026-05-20
Malware distribution method revealed
Victims are prompted to download ZIP archives containing malware disguised as official tax documents.
CybersecuritynewsMore articles in this cluster (2)
Continue Reading
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…
Critical RCE Vulnerability in F5 BIG-IP APM Exploited in the Wild A severe heap-based buffer overflow vulnerability, tracked as CVE-2026-94127, has been identified in F5 BIG-IP Access Policy Manager (APM), allowing unauthenticated remote code execution (RCE) on the Traffic Management Microkernel (TMM) data plane. This vulnerability is triggered when both an APM access policy and an…