Cyber Security News

New Phishing Attack Mimic as Income Tax Department of India Delivers AsyncRAT

A comprehensive phishing operation began targeting Indian companies in November 2025 by impersonating the Income Tax Department of India.

The campaign employed remarkably authentic government communication templates, bilingual messaging in Hindi and English, and legal references to sections of the Income Tax Act to create a sense of legitimacy and urgency.

The emails warned recipients of alleged tax irregularities and demanded that they submit documents within 72 hours, using psychological pressure as a primary weapon to drive users to open malicious attachments.

The attack delivered a sophisticated two-stage malware chain that began with password-protected ZIP files containing shellcode loaders and later evolved to use Google Docs links for secondary payload delivery.

The final payload was a Remote Access Trojan designed to grant attackers complete control over compromised systems, including capabilities for screen sharing, file transfer, and remote command execution.

The campaign specifically targeted securities firms, financial companies, and non-banking financial corporations that regularly exchange regulatory documents with government agencies.

Raven security analysts identified the zero-day phishing campaign by recognizing multiple layers of inconsistency within the attack structure, ultimately preventing widespread infection across targeted organizations.

Infection mechanism of this campaign

The infection mechanism of this campaign reveals a carefully engineered approach to evasion.

Initial phishing emails originated from legitimate QQ.com free email accounts that passed SPF, DKIM, and DMARC authentication checks, a critical factor in bypassing traditional email security filters.

Phishing Email #1 (Source – Raven)

The attachments used password protection to prevent antivirus engines from scanning their contents during transit.

Phishing Email #2 (Source – Raven)

When users extracted the ZIP files with passwords provided in the emails, they encountered executable files named “NeededDocuments” that contained shellcode designed to execute through regsvr32 proxy loading.

This technique, commonly known as fileless execution, allowed the malware to load a hidden DLL directly into memory without writing detectable signatures to the disk.

The shellcode established persistence mechanisms, harvested stored credentials from the victim’s system, and opened communication channels to remote command servers associated with AsyncRAT infrastructure.

Some variants used Google Docs as a trusted hosting platform for the second stage, exploiting the inherent trust placed in legitimate cloud services by corporate security filters.

The combination of clean sender authentication, password-protected payloads, legitimate cloud infrastructure, and regsvr32 proxy execution created a nearly invisible attack chain that rendered signature-based detection methods ineffective.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago