Tax-Themed Phishing Emails Deliver In-Memory Malware to Windows Users

Cybersecurity researchers have uncovered a highly sophisticated phishing campaign that uses tax-themed emails to deliver advanced in-memory malware to Windows users.

The malicious operation relies heavily on social engineering and government impersonation to trick victims into compromising their own systems.

Cyfirma threat analysts recently detailed this multi-stage attack framework, highlighting its ability to bypass conventional security solutions.

The campaign primarily starts with a fraudulent tax notification email that perfectly mimics the official Indian Income Tax Department.

The attackers use urgency-driven messaging and threats of financial penalties to manipulate their targets into acting quickly.

The cybersecurity community notes that these emails successfully bypass common email security filters because the attackers use legitimate third-party email delivery services and spoofed identities.

Once a user clicks the provided link, they are redirected to a carefully crafted phishing website that looks identical to a genuine government tax portal.

This fake portal features bilingual text in English and Hindi, along with official logos, to establish immediate trust with the victim.

Tax Phishing Drops Malware (Source: cyfirma)
Tax Phishing Drops Malware (Source: cyfirma)

Tax Phishing Drops Malware

When the victim visits the fake government portal, they are instructed to download what appears to be an urgent tax compliance document.

This document is actually a malicious ZIP archive containing three distinct files designed to work together.

Cyfirma researchers explained that this modular approach separates the attack into distinct stages, making it much harder for standard antivirus software to detect the threat.

Tax Phishing Drops Malware (Source: cyfirma)
Tax Phishing Drops Malware (Source: cyfirma)

The first file is an executable program named in Hindi that serves as the initial loader and prepares the system environment.

When the user runs this file, it cleverly abuses a legitimate Windows feature to load the second file, a malicious dynamic link library, instead of the safe system file it usually looks for.

This technique, known as DLL Search Order Hijacking, allows attackers to execute unauthorized code. To further protect itself from discovery, the malware uses multiple layers of obfuscation and complex encryption.

Tax-themed phishing webpage impersonating an Indian Tax department using government branding, bilingual content, urgency-based messaging, and a malicious download mechanism to facilitate social engineering-based malware delivery (Source: cyfirma)
Tax-themed phishing webpage impersonating an Indian Tax department using government branding, bilingual content, urgency-based messaging, and a malicious download mechanism to facilitate social engineering-based malware delivery (Source: cyfirma)

Threat intelligence analysts discovered that the malicious code uses a customized encryption method based on the RC4 cipher to hide its true purpose from security scanners.

The malware also constantly alters its internal execution paths, making it incredibly difficult for automated security tools to recognize its signature.

Once the malware is fully active in memory, it establishes a persistent connection to the attacker’s command-and-control servers.

Cyfirma experts noted that the malware communicates via WebSockets over standard internet protocols, allowing its malicious traffic to blend seamlessly with everyday web browsing.

This network traffic can even navigate through corporate proxy servers, bypassing strict enterprise network restrictions.

Indicators of Compromise

Indicator TypeFile Name / ValueDescriptionMD5 Hash
Executableकर विवरण.exe Stage 0 Host Loader and initial execution vector 3a8f6454927b8993aded75de0de2bd00
Dynamic Link LibrarySbieDll.dll Stage 1 Polymorphic Loader DLL used for API hooking and evasion e83ff54e58f0b295a392c7fc39a7d0de
BinarySbieDll.bin Stage 2 Encrypted Shellcode Payload b498256cb086a6962077cdd6d2f65327

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories