ITR Filing Alert: China-Linked Hackers Deploy Fake Income Tax Notices to Infect Devices

The420.in Staff
4 Min Read

A large-scale phishing and malware campaign impersonating India’s Income Tax Department and the Ministry of Finance has been uncovered during the ongoing Income Tax Return (ITR) filing season. According to a cybersecurity investigation, the alleged China-linked operation is targeting taxpayers and businesses by sending official-looking emails designed to trick recipients into installing malware on their computers. Investigators believe the campaign has been strategically launched during the Assessment Year 2026–27, when taxpayers are more likely to trust communications related to tax compliance.

According to an investigation conducted by cybersecurity and counter-threat intelligence firm Shreshta IT Technologies Pvt. Ltd., victims receive a bilingual (Hindi-English) “Office Memorandum” that appears to be an official government communication. The email alleges tax irregularities and instructs recipients to submit documents within 72 hours, warning of legal action if they fail to comply. However, the attached document actually contains malware which, once opened, can silently compromise the victim’s computer and provide attackers with remote access.

India’s Largest Cybercrime Conference Nears: FutureCrime Summit 2026 Set for 6–7 August at Bharat Mandapam

The investigation found that the campaign operates through 379 spoofed domains resembling official Income Tax Department and government websites. These domains are reportedly hosted through service providers based in China and Hong Kong. Researchers also identified multiple technical indicators linking the campaign to China, including Chinese-language artefacts embedded within phishing pages and the use of the Open Fixed-layout Document (OFD) format, a document standard widely used in China.

According to Swapneel Patnekar, Chief Executive Officer of Shreshta IT Technologies, the campaign has been carefully designed to exploit public trust in government institutions. He said the emails appear highly authentic and create a sense of urgency by imposing a 72-hour deadline, pressuring recipients into opening malicious attachments. He also emphasised that the Income Tax Department does not issue penalty notices through public email services such as Gmail or Outlook, and any such communication should be treated as suspicious.

During the investigation, cybersecurity researchers identified 18 suspicious IP addresses, 11 of which were allegedly linked to Alibaba and other Chinese cloud service providers. Experts believe the campaign primarily targets urban taxpayers, as they are more likely to file income tax returns. The phishing emails typically contain references to penalties, compliance failures, fines, or urgent legal action to create panic and persuade recipients to download the attached files without verification.

Cybersecurity experts warn that once users download and execute the malicious attachment, malware can be installed on their devices. In some cases, the computer may freeze briefly while attackers gain access to sensitive information, including login credentials, financial records, and confidential personal data. Such malware can later be used for remote access, identity theft, financial fraud, or broader cyber espionage activities.

Experts have advised taxpayers and businesses to verify all tax-related communications only through the official Income Tax portal before taking any action. Users should never download .exe files, compressed folders such as ZIP or RAR, or other executable attachments received through unsolicited emails. Any message demanding immediate compliance or threatening legal action should be independently verified before responding.

Cybersecurity professionals further recommend avoiding suspicious links and email attachments altogether. If a malicious file is accidentally downloaded, users should immediately disconnect the affected system from the internet and seek professional technical assistance. Any suspected phishing attempt or cyber fraud should be reported without delay through the National Cyber Crime Helpline (1930) or the National Cyber Crime Reporting Portal. Prompt reporting can significantly improve the chances of limiting financial losses, containing the cyberattack, and assisting law enforcement agencies in tracing those responsible.

Stay Connected