Breaking News
Cybercriminals are exploiting India's ongoing Income Tax Return (ITR) filing season by distributing fake Income Tax Department notices over WhatsApp and other messaging platforms to infect taxpayers' devices with malware and steal banking credentials, according to cybersecurity firm CloudSEK.
The campaign uses forged government documents, cloned tax-filing websites and malicious software to trick victims into revealing sensitive financial information or granting attackers remote access to their devices.
According to CloudSEK's analysis, attackers are taking advantage of taxpayers' expectations of refunds and fears of penalties by sending convincing notices carrying the Government of India emblem, fabricated reference numbers and citations from the Income Tax Act. The messages typically demand that recipients respond within 72 hours, creating a sense of urgency.
"The Income Tax Department does not send statutory notices, penalty orders or summons over WhatsApp," said Shobhit Mishra, Threat Intelligence Researcher at CloudSEK. He said the campaign combines convincing government impersonation with malware delivery to bypass both human judgement and conventional security controls.
Researchers observed the fake notices being circulated through WhatsApp accounts using seemingly legitimate names, including compromised personal and business accounts. Victims receive a ZIP archive named ITD.zip, which contains malware instead of tax documents. CloudSEK found multiple versions of the archive with varying file sizes, suggesting attackers are regularly modifying the payloads to evade malware detection systems.
The campaign targets both Android and Windows users. On Android devices, the malicious application can intercept SMS messages and one-time passwords, harvest contacts, steal credentials and display fake banking screens to capture financial information.
Windows users are lured into executing a malicious file disguised as a legitimate Microsoft system process. According to CloudSEK, the malware uses a valid Extended Validation (EV) digital certificate to appear trustworthy before downloading additional payloads. It also employs anti-analysis techniques, including sandbox detection and in-memory code execution, making it more difficult for conventional security tools to identify.
In addition to messaging-based attacks, CloudSEK identified multiple phishing websites impersonating the Income Tax Department. The fake portals display forged tax notices and prompt users to download supposed documents, which instead install malware. The domains use low-trust extensions and imitate the government's e-filing portal but are unrelated to the official incometax.gov.in website.
Researchers said the campaign forms part of a broader tax-season fraud ecosystem that also includes fake refund notifications, cloned e-filing portals, fraudulent e-PAN verification emails and scammers posing as tax consultants offering expedited refunds.
CloudSEK advised taxpayers to ignore tax notices received through WhatsApp or SMS and verify all communications directly through the official Income Tax Department portal. Users who have opened suspicious files should immediately disconnect affected devices from the network, change passwords using a clean device, enable multi-factor authentication, perform a full malware scan and report the incident through the National Cybercrime Helpline or the government's Cyber Crime Reporting Portal.
The campaign highlights how cybercriminals continue to exploit seasonal events and government processes to increase the credibility of phishing attacks, making tax-filing periods a recurring target for financially motivated threat actors.
The campaign uses forged government documents, cloned tax-filing websites and malicious software to trick victims into revealing sensitive financial information or granting attackers remote access to their devices.
According to CloudSEK's analysis, attackers are taking advantage of taxpayers' expectations of refunds and fears of penalties by sending convincing notices carrying the Government of India emblem, fabricated reference numbers and citations from the Income Tax Act. The messages typically demand that recipients respond within 72 hours, creating a sense of urgency.
"The Income Tax Department does not send statutory notices, penalty orders or summons over WhatsApp," said Shobhit Mishra, Threat Intelligence Researcher at CloudSEK. He said the campaign combines convincing government impersonation with malware delivery to bypass both human judgement and conventional security controls.
Researchers observed the fake notices being circulated through WhatsApp accounts using seemingly legitimate names, including compromised personal and business accounts. Victims receive a ZIP archive named ITD.zip, which contains malware instead of tax documents. CloudSEK found multiple versions of the archive with varying file sizes, suggesting attackers are regularly modifying the payloads to evade malware detection systems.
The campaign targets both Android and Windows users. On Android devices, the malicious application can intercept SMS messages and one-time passwords, harvest contacts, steal credentials and display fake banking screens to capture financial information.
Windows users are lured into executing a malicious file disguised as a legitimate Microsoft system process. According to CloudSEK, the malware uses a valid Extended Validation (EV) digital certificate to appear trustworthy before downloading additional payloads. It also employs anti-analysis techniques, including sandbox detection and in-memory code execution, making it more difficult for conventional security tools to identify.
In addition to messaging-based attacks, CloudSEK identified multiple phishing websites impersonating the Income Tax Department. The fake portals display forged tax notices and prompt users to download supposed documents, which instead install malware. The domains use low-trust extensions and imitate the government's e-filing portal but are unrelated to the official incometax.gov.in website.
Researchers said the campaign forms part of a broader tax-season fraud ecosystem that also includes fake refund notifications, cloned e-filing portals, fraudulent e-PAN verification emails and scammers posing as tax consultants offering expedited refunds.
CloudSEK advised taxpayers to ignore tax notices received through WhatsApp or SMS and verify all communications directly through the official Income Tax Department portal. Users who have opened suspicious files should immediately disconnect affected devices from the network, change passwords using a clean device, enable multi-factor authentication, perform a full malware scan and report the incident through the National Cybercrime Helpline or the government's Cyber Crime Reporting Portal.
The campaign highlights how cybercriminals continue to exploit seasonal events and government processes to increase the credibility of phishing attacks, making tax-filing periods a recurring target for financially motivated threat actors.
See What’s Next in Tech With the Fast Forward Newsletter
START - UP
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




