Cybercriminals are taking advantage of the ITR deadline rush in India, distributing fake government notices with malware-laden ZIP attachments and launching cloned e-filing portals to steal bank credentials.

Cybercriminals Target Taxpayers with Malware and Cloned Portals Amid ITR Filing Rush

The420 Web Correspondent
3 Min Read

As millions of taxpayers scramble to meet income-tax return (ITR) deadlines, submit compliance disclosures, and track pending refunds, cybercriminals are unleashing a wave of targeted cyberattacks across the country. Cybersecurity analytics firm CloudSEK has issued a critical alert highlighting dual phishing and malware campaigns designed to impersonate the Income Tax Department. Attackers are exploiting the high volume of official communications expected during filing season, relying on psychological pressure and authentic-looking digital assets to compromise personal devices and steal sensitive financial credentials.

Malicious Attachments and Forged Government Notices

One of the primary attack vectors currently circulating across messaging channels involves WhatsApp messages containing forged official documents. Distributed from unverified or compromised user accounts, these fraudulent messages carry mock “office memorandums” complete with the emblem of the Government of India, bilingual text in English and Hindi, fabricated tracking reference numbers, and the forged signature of a tax officer. To maximize urgency, the fake notices allege severe non-compliance and discrepancies under Section 271(1)(c) of the Income Tax Act, threatening immediate criminal prosecution under Section 276C unless the recipient responds within a strict 72-hour window.

Rather than directing victims to official administrative portals, the attackers instruct recipients to open an attached compressed file typically labeled as ITD.zip. Once extracted on an Android smartphone, the archive installs concealed spyware that operates silently in the background. This malware intercepts incoming SMS messages—including critical banking one-time passwords (OTPs)—and harvested contact lists, while logging keystrokes to capture personal account passwords. In more aggressive variants, the malicious software projects overlay screens over mobile banking and digital payment applications, tricking users into revealing authentication codes directly to fraudsters.

Cloned E-Filing Web Portals and Security Recommendations

Simultaneously, cybercriminal groups are deploying widespread network campaigns utilizing fake websites engineered to mirror the layout and appearance of the official income-tax e-filing portal. Victims are steered to these cloned destinations through malicious web links embedded in SMS messages, fraudulent search engine advertisements, and unsolicited emails. Once on the fake portal, users are prompted to enter their permanent account numbers, identity verification details, account passwords, security answers, and banking credentials, granting attackers full remote access to their financial accounts.

Tax authorities and cybersecurity experts advise taxpayers to exercise extreme vigilance and observe standard government operating procedures during the filing rush. The Income Tax Department does not send compressed zip archives, executable app installers, or official legal notices via WhatsApp or non-government messaging apps. All official statutory notices, refund statuses, and compliance queries are communicated through registered email addresses, official SMS sender handles, or directly within the authenticated user dashboard at the official e-filing portal. Taxpayers who receive suspicious messages are urged to verify notices directly on the official portal and report fraudulent communications to the national cybercrime helpline or official reporting channels.

Stay Connected