Cybercriminals Exploit ITR Filing Rush with Malware and Fake Tax Portals

www.news4hackers.com-cybercriminals-exploit-itr-filing-rush-with-malware-and-fake-tax-portals-cybercriminals-exploit-itr-filing-rush-with-malware-and-fake-tax-portals

As India’s income-tax return (ITR) filing season intensifies, malicious actors are leveraging the heightened demand for official communications to execute sophisticated phishing and malware operations.

Malicious Attachments and Forged Government Notices

A primary method involves distributing falsified official notices via unverified messaging platforms. These communications feature counterfeit documents bearing the Government of India’s emblem, bilingual content in English and Hindi, and fabricated reference numbers. The messages reference Section 271(1)(c) of the Income Tax Act, falsely alleging non-compliance and warning of potential criminal charges under Section 276C if no action is taken within 72 hours.

Malware Distribution via ZIP Files

Recipients are directed to open attached ZIP files, typically labeled as ITD.zip, which install covert surveillance software on Android devices. This malware operates discreetly, intercepting SMS messages—including banking one-time passwords—and extracting contact lists. It also logs keystrokes to capture login credentials for financial accounts.

Overlay Attacks on Banking Apps

Advanced variants employ overlay attacks, displaying fake login screens over banking apps to extract authentication codes directly from users.

Cloned E-Filing Web Portals and Security Recommendations

Simultaneously, threat actors are deploying fake websites designed to replicate the official income-tax e-filing portal. These domains are distributed through malicious links in SMS messages, fraudulent search engine ads, and unsolicited emails. Users redirected to these sites are prompted to enter personal identifiers such as permanent account numbers, verification details, and banking information, granting attackers access to financial systems.

Government and Cybersecurity Advice

The Income Tax Department does not distribute official notices, refund updates, or compliance alerts via non-government messaging apps or compressed file attachments. All legitimate interactions occur through secure, authenticated platforms. Taxpayers are advised to verify the authenticity of any communication by cross-referencing details with the official e-filing portal.

Risk Mitigation Strategies

Enabling multi-factor authentication for financial accounts and avoiding unsolicited links can mitigate risks associated with these campaigns.

The420.in Developed by Brainfox Infotech Cybercriminals are taking advantage of the ITR deadline rush in India, distributing fake government notices with malware-laden ZIP attachments and launching cloned e-filing portals to steal bank credentials.

SHARE As millions of taxpayers scramble to meet income-tax return (ITR) deadlines, submit compliance disclosures, and track pending refunds, cybercriminals are unleashing a wave of targeted cyberattacks across the country.

Contents

  • Malicious Attachments and Forged Government Notices

  • Cloned E-Filing Web Portals and Security Recommendations

One of the primary attack vectors currently circulating across messaging channels involves messages containing forged official documents. Distributed from unverified or compromised user accounts, these fraudulent messages carry mock “office memorandums” complete with the emblem of the Government of India, bilingual text in English and Hindi, fabricated tracking reference numbers, and the forged signature of a tax officer.

Urgency and Legal Threats

To maximize urgency, the fake notices allege severe non-compliance and discrepancies under Section 271(1)(c) of the Income Tax Act, threatening immediate criminal prosecution under Section 276C unless the recipient responds within a strict 72-hour window.

Redirects to Malicious Files

Rather than directing victims to official administrative portals, the attackers instruct recipients to open an attached compressed file typically labeled as ITD.zip. Once extracted on an Android smartphone, the archive installs concealed spyware that operates silently in the background.

Malware Capabilities

This malware intercepts incoming SMS messages—including critical banking one-time passwords (OTPs)—and harvested contact lists, while logging keystrokes to capture personal account passwords. In more aggressive variants, the malicious software projects overlay screens over mobile banking and digital payment applications, tricking users into revealing authentication codes directly to fraudsters.

Cloned E-Filing Web Portals and Security Recommendations

Simultaneously, cybercriminal groups are deploying widespread network campaigns utilizing fake websites engineered to mirror the layout and appearance of the official income-tax e-filing portal. Victims are steered to these cloned destinations through malicious web links embedded in SMS messages, fraudulent search engine advertisements, and unsolicited emails.

Phishing for Financial Data

Once on the fake portal, users are prompted to enter their permanent account numbers, identity verification details, account passwords, security answers, and banking credentials, granting attackers full remote access to their financial accounts.

Government and Expert Guidance

Tax authorities and cybersecurity experts advise taxpayers to exercise extreme vigilance and observe standard government operating procedures during the filing rush. The Income Tax Department does not send compressed zip archives, executable app installers, or official legal notices via or non-government messaging apps.

All official statutory notices, refund statuses, and compliance queries are communicated through 📲 Join Our Channel Stay Connected .



About Author

en_USEnglish