Fake Tax-Themed Phishing Campaign Delivers Malware

    Date: 09/16/2026

    Severity: High

    Summary

    A malware campaign uses a fake Indian Income Tax Department assessment notice to distribute a RAT-like payload targeting Windows systems. The attackers operate ten malicious domains hosting a fraudulent tax assessment portal designed to mimic official government communications. Victims are tricked into downloading a malicious VHDX file disguised as an official ITR-1 to ITR-4 offline utility for FY2025–26. The mounted VHDX delivers a loader executable and malicious `tedutil.dll`, which is extracted from the executable’s embedded resources and executed. The staged malware provides RAT-like capabilities, including persistence, system reconnaissance, command execution, and remote communication.

    Indicators of Compromise (IOC) List  

    Domain/URLs

    zasxcd.shop

    ssefcv.shop

    cbvfrd.shop

    bvnbhy.shop

    bmnjhy.shop

    mkjiun.shop

    nmhjnu.shop

    zxcdfr.shop

    sfbnhy.shop

    xvbndr.shop

    IP Address

    103.59.103.170

    103.97.128.245

    Hash

    518ee4c9ae0321bd4fe8616e4f195f0079c6503109d2710e80e09d1a0f1dc98f

    f4ae0f7c0c663e41dab28b2992f1afa9b97fe13a52f2d1fa26156554a23b99a7

    71d15f3c13f5b11866cf65d9cf014236a47d221155ae992d9992abccedb66cf2

    Filename 

    Common_Offline_Utility_ITR-1_to_4_AY2026-07-27.vhdx

    Common_Offline_Utility_ITR-1_to_4_AY2026-27.exe 

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "cbvfrd.shop" or url like "cbvfrd.shop" or siteurl like "cbvfrd.shop" or domainname like "sfbnhy.shop" or url like "sfbnhy.shop" or siteurl like "sfbnhy.shop" or domainname like "zxcdfr.shop" or url like "zxcdfr.shop" or siteurl like "zxcdfr.shop" or domainname like "xvcbvgfr.com" or url like "xvcbvgfr.com" or siteurl like "xvcbvgfr.com" or domainname like "bmnjhy.shop" or url like "bmnjhy.shop" or siteurl like "bmnjhy.shop" or domainname like "bvnbhy.shop" or url like "bvnbhy.shop" or siteurl like "bvnbhy.shop" or domainname like "nmhjnu.shop" or url like "nmhjnu.shop" or siteurl like "nmhjnu.shop" or domainname like "ssefcv.shop" or url like "ssefcv.shop" or siteurl like "ssefcv.shop" or domainname like "xvbndr.shop" or url like "xvbndr.shop" or siteurl like "xvbndr.shop" or domainname like "mkjiun.shop" or url like "mkjiun.shop" or siteurl like "mkjiun.shop" or domainname like "zasxcd.shop" or url like "zasxcd.shop" or siteurl like "zasxcd.shop"

    Detection Query 2 :

    dstipaddress IN ("103.59.103.170","103.97.128.245") or srcipaddress IN ("103.59.103.170","103.97.128.245")

    Detection Query 3 :

    sha256hash IN ("71d15f3c13f5b11866cf65d9cf014236a47d221155ae992d9992abccedb66cf2","f4ae0f7c0c663e41dab28b2992f1afa9b97fe13a52f2d1fa26156554a23b99a7","518ee4c9ae0321bd4fe8616e4f195f0079c6503109d2710e80e09d1a0f1dc98f")

    Reference: 

    https://www.cyfirma.com/research/fake-tax-themed-phishing-campaign-delivers-malware/      


    Tags

    MalwareRATPhishingIndiaGovernment Services and FacilitiesFinancial ServicesMimicLoader

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags