The report, Tax Season, Open Season: Phishing and Malware Campaigns Targeting Indian Taxpayers, is based on scam samples shared by victims on X and phishing infrastructure analysed by CloudSEK researchers.

FinTech BizNews Service
Mumbai, July 30, 2026: Cybercriminals are exploiting India's Income Tax Return (ITR) filing season with fake Income Tax Department notices delivered over WhatsApp and other messaging apps. The campaign uses forged government documents, cloned e-filing portals and malware to steal banking credentials and gain remote access to victims' devices.
These findings come from a new report by CloudSEK, an AI-native predictive cyber intelligence company. The report, Tax Season, Open Season: Phishing and Malware Campaigns Targeting Indian Taxpayers, is based on scam samples shared by victims on X and phishing infrastructure analysed by CloudSEK researchers.
CloudSEK found that attackers are exploiting taxpayers' fear of penalties and expectation of refunds. The campaign uses convincing government branding, legal references and strict deadlines to pressure victims into acting without verification.
"Tax season gives attackers the perfect opportunity to exploit trust and urgency. People expect messages about refunds, notices and compliance deadlines. This campaign combines convincing government impersonation with sophisticated malware delivery to bypass both human judgement and traditional security controls. Taxpayers should remember one simple rule: the Income Tax Department does not send statutory notices, penalty orders or summons over WhatsApp," said Shobhit Mishra, Threat Intelligence Researcher, CloudSEK.
Forged tax notices delivered over WhatsApp
The attackers send a fake Office Memorandum through WhatsApp and other messaging apps. The notice carries the Government of India emblem, bilingual Hindi-English text, fabricated reference numbers and a fake signatory claiming to be "Raj Kumar Sharma, Assistant Commissioner of Income Tax." It cites Section 271(1)(c) and Section 276C of the Income Tax Act and gives recipients just 72 hours to respond.
CloudSEK observed these messages coming from unknown or compromised WhatsApp accounts with names such as "Sunil Sharma," "jankiforex" and "Hotel Oyster." In one case, attackers shared the file in a WhatsApp group. The attachment, ITD.zip, does not contain tax documents. It delivers malware instead. (For More Information, Read Full Report)
Researchers found multiple versions of the archive ranging from 2 MB to 35 MB. The changing file sizes indicate payload rotation, a technique attackers use to bypass traditional malware detection.
Android and Windows users both targeted
On Android devices, the ZIP installs a malicious APK. The malware can intercept SMS messages and banking OTPs, steal credentials, harvest contacts and display fake banking screens to capture sensitive information.
Windows users receive a malicious executable named ITD_Tax_Notice.exe. CloudSEK's analysis confirmed that it masquerades as Microsoft's svchost.exe, uses a valid Extended Validation (EV) certificate to appear trustworthy, and downloads a second-stage payload from Alibaba Cloud.
The malware also profiles the victim, checks whether it is running inside a sandbox and executes additional code directly in memory. These techniques make the malware significantly harder to detect using traditional security tools.
Attackers also cloned Income Tax websites
CloudSEK identified dozens of newly registered domains impersonating the Income Tax Department. These websites host the same forged penalty notice and ask users to click a "Download Documents" button. Instead of downloading documents, the button installs malware.
Researchers found these phishing sites on disposable domains using low-trust TLDs such as .lol, .xin, .ink and .autos. None of them belong to the official incometax.gov.in domain. Attackers can quickly replace these domains as older ones are blocked. (For More Information, Read Full Report)
Part of a wider tax fraud ecosystem
CloudSEK also identified several parallel campaigns targeting taxpayers during the filing season:
All these campaigns use the same tactic. They create urgency, impersonate trusted institutions and trick victims into sharing credentials or installing malware.
CloudSEK's advice
CloudSEK advises taxpayers to ignore any Income Tax notice received through WhatsApp or SMS. Users should access the Income Tax portal only by typing incometax.gov.in directly into their browser and verify every notice independently.
Anyone who has opened ITD.zip or a similar file should disconnect the device immediately, change passwords from a clean device, enable multi-factor authentication, run a full malware scan and report the incident through the National Cybercrime Helpline (1930) or the Cyber Crime Reporting Portal.
Similarly, CloudSEK advises businesses to reinforce tax-season awareness briefings for finance and HR teams, block suspicious domains where possible, review archive and disk-image files carefully, and route all tax filings through verified in-house or authorised professionals.