
Cybersecurity researchers have uncovered a sophisticated phishing campaign targeting Indian taxpayers, chartered accountants and corporate finance teams during the income tax filing season. The attackers are impersonating the Income Tax Department by sending official-looking emails and documents that trick victims into downloading malware capable of taking complete control of their computers. According to researchers from CloudSEK, the campaign highlights how cybercriminals are exploiting the urgency of tax compliance to steal sensitive financial and personal information. As CoinDCX co-founder Sumit Gupta warns, genuine refunds rarely arrive immediately after filing, and messages claiming "refund approved" while demanding urgent updates should be treated as warning signs.
India's tax-filing rush is colliding with its expanding cryptocurrency market, creating a timely opening for phishing gangs. India ranked first in Chainalysis' 2025 Global Crypto Adoption Index, covering centralized platforms, retail activity, decentralized finance, and institutional transfers. The India ITR process now includes exchange statements, wallet histories, token disposals, and tax deduction records, making cryptocurrency another reporting area requiring detailed reconciliation. According to CoinDCX, crypto tax records can reveal exchange accounts, transaction histories, and wallet information that can help criminals tailor follow-up messages or target financial services. However, no legitimate tax process requires a wallet seed phrase or private key - these credentials provide direct control over digital assets and should never appear in any tax form.
In the WhatsApp campaign, victims receive an 'office memorandum' from an unknown or compromised account masquerading as the income tax department. According to CloudSek's report, the forged document features the government of India emblem, bilingual English and Hindi text, fabricated reference numbers and the name of a fake tax official to appear authentic. The notice falsely claims that discrepancies have been detected under Sec 271(1)(c) of the Income Tax Act and warns of prosecution under Sec 276C, giving recipients just 72 hours to respond. As reported by CloudSek, attackers are using two primary methods: malware-laden WhatsApp attachments and phishing websites that closely mimic the official income-tax e-filing portal. The campaign comes at a time when millions of taxpayers are expecting messages related to refunds, notices and compliance deadlines, making them more likely to trust official-looking communications.
Instead of including a web link, the message carries a ZIP attachment named 'ITD.zip', presented as tax documents. On Android devices, opening the file installs malware capable of accessing SMS messages, including banking one-time passwords (OTPs), contacts and keystrokes. As reported by CloudSek, the malware can also overlay fake login screens on banking and payment applications to capture usernames, passwords, and other sensitive information. According to researchers, the malware uses sophisticated techniques such as DLL hijacking and legitimate software components to avoid detection by security tools. The malware deployed in the campaign is a Remote Access Trojan (RAT) that silently installs itself without obvious signs of infection.
Cybersecurity experts recommend several precautions to protect against these sophisticated attacks: never open tax-related attachments received through unsolicited emails, verify any notice directly through the official Income Tax portal instead of clicking email links, check the sender's email address carefully before responding, keep antivirus software enabled and updated, avoid downloading files from unknown websites, and ensure Windows and other software are updated with the latest security patches. For crypto users, the strongest defense is to separate notification from action - taxpayers should read alerts but open the Income Tax Department portal manually or through a bookmark. Users should preserve exchange statements, transaction hashes, wallet addresses, acquisition costs, and TDS certificates, and never enter seed phrases or private keys into tax forms or refund pages. Anyone who clicks a suspicious link should immediately change affected passwords, contact the relevant bank or exchange, and report financial fraud through helpline 1930 or the National Cyber Crime Reporting Portal.