Cybersecurity researchers have uncovered a highly sophisticated phishing campaign that uses tax-themed emails to deliver advanced in-memory malware to Windows users.
The malicious operation relies heavily on social engineering and government impersonation to trick victims into compromising their own systems.
Cyfirma threat analysts recently detailed this multi-stage attack framework, highlighting its ability to bypass conventional security solutions.
The campaign primarily starts with a fraudulent tax notification email that perfectly mimics the official Indian Income Tax Department.
The attackers use urgency-driven messaging and threats of financial penalties to manipulate their targets into acting quickly.
The cybersecurity community notes that these emails successfully bypass common email security filters because the attackers use legitimate third-party email delivery services and spoofed identities.
Once a user clicks the provided link, they are redirected to a carefully crafted phishing website that looks identical to a genuine government tax portal.
This fake portal features bilingual text in English and Hindi, along with official logos, to establish immediate trust with the victim.

Tax Phishing Drops Malware
When the victim visits the fake government portal, they are instructed to download what appears to be an urgent tax compliance document.
This document is actually a malicious ZIP archive containing three distinct files designed to work together.
Cyfirma researchers explained that this modular approach separates the attack into distinct stages, making it much harder for standard antivirus software to detect the threat.

The first file is an executable program named in Hindi that serves as the initial loader and prepares the system environment.
When the user runs this file, it cleverly abuses a legitimate Windows feature to load the second file, a malicious dynamic link library, instead of the safe system file it usually looks for.
This technique, known as DLL Search Order Hijacking, allows attackers to execute unauthorized code. To further protect itself from discovery, the malware uses multiple layers of obfuscation and complex encryption.

Threat intelligence analysts discovered that the malicious code uses a customized encryption method based on the RC4 cipher to hide its true purpose from security scanners.
The malware also constantly alters its internal execution paths, making it incredibly difficult for automated security tools to recognize its signature.
Once the malware is fully active in memory, it establishes a persistent connection to the attacker’s command-and-control servers.
Cyfirma experts noted that the malware communicates via WebSockets over standard internet protocols, allowing its malicious traffic to blend seamlessly with everyday web browsing.
This network traffic can even navigate through corporate proxy servers, bypassing strict enterprise network restrictions.
Indicators of Compromise
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.