AI Stories on SHORT INFO are generated & curated with AI
unverified 09 Jul, 19:11

China-linked campaign uses fake Indian income-tax notices to deploy two remote-access trojans

Opening a fake Indian income-tax notice right now can install two remote-access trojans. Cyderes traced a China-linked campaign that abuses a signed Windows app to side-load malware, running a Gh0st RAT and a Quasar-family implant in memory, per The Hacker News.

A phishing campaign impersonating India's Income Tax Department is delivering not one but two remote-access trojans to victims who open what looks like an official tax notice, according to researchers at Cyderes and reporting by The Hacker News. The operation, which analysts suspect is China-linked, leans on the urgency of tax season and convincing government branding to pressure people into downloading a fake tax utility. The technical design is what makes it notable. Rather than dropping obvious malware, the attackers ship a legitimate, digitally signed Windows executable alongside a malicious DLL named nvdaHelperRemote.dll. When the trusted program runs, Windows loads the attacker's DLL instead of the genuine one, a technique called DLL side-loading that lets the malware ride in on a trusted process. From there the infection unfolds across six stages and ends with two independent implants running quietly in memory: a Gh0st RAT derivative and a .NET implant related to the Quasar and AsyncRAT families. Each communicates with its own command-and-control server, giving the attacker redundant access if one channel is blocked or detected. The practical takeaway for anyone filing taxes online: government tax agencies do not send downloadable utilities or executables by email. Verify notices directly through the official portal rather than any link or attachment. Source: The Hacker News, Cyderes.

Published on
FacebookThreadsXBluesky