A compliance-themed phishing wave aimed at Indian taxpayers shows how official-looking pressure and a signed Windows executable can work together to move remote-access malware onto a victim machine.
A tax-branded phishing operation uses a lookalike portal and a disk-image attachment to exploit trust, urgency, and the habit of opening official-looking files.
Tax-branded phishing emails are being used to deliver in-memory malware on Windows, a tactic that shifts detection away from saved files and toward what happens after a user opens the attachment.
A tax lure is only the first move; the harder part for defenders is the kind of malware that may run in memory and leave fewer clues on disk.
A lure built around Indian tax assessment and penalty pages is being used to push Windows users toward a download chain that turns an “official” file into malware risk.