Fake Tax Emails Are Planting Two Separate Spying Tools on Indian Taxpayers' Computers

A campaign timed to India's tax filing season tricks people into downloading what looks like an official government utility, and inside are two hidden programs that give criminals full remote control of the victim's machine.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a laptop screen glowing in a dim room showing a formal government tax portal interface with official-looking
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Security firm Cyderes discovered a 2025 phishing campaign in which criminals send fake emails impersonating India's Income Tax Department.
  • The fake emails push a download that secretly installs two remote-access trojans, programs that let an outside attacker control your computer as if they were sitting at the keyboard.
  • One trojan is based on Gh0st RAT, a long-established spying tool; the second comes from the QuasarRAT and AsyncRAT family, both widely used by criminal groups.
  • Each trojan calls home to its own separate server, so blocking one doesn't cut off the attacker's access.
  • Cyderes recommends behaviour-based detection rather than relying on signature lists alone.

Every year, as India's tax season opens, millions of people expect emails about their filings. Criminals know this. Researchers at Cyderes have found a campaign that uses the rush and anxiety of tax season as cover for a serious attack.

Victims receive an email that looks like it comes from the Indian Tax Department, pressuring them into downloading what appears to be an official income-tax utility with convincing government branding. It isn't official. A trap.

How do the criminals stay hidden once they are inside?

They don't do anything that looks obviously suspicious. The attack unfolds in quiet stages rather than dropping malicious software the moment someone opens the file.

The download contains a legitimate, digitally signed Windows program called COU_ITR-1_to_4_AY2026-27.exe. Windows trusts signed programs, so security tools are less likely to flag it. The criminals abuse that trust by placing a malicious library file, a DLL (a bundle of code a program loads when it starts), in the folder the trusted program checks first, giving their code a clean entry point.

From there, the attack checks for administrator rights, patches AMSI (the Antimalware Scan Interface, which normally lets security software inspect what a program is about to run), and injects itself into svchost.exe, a standard Windows background process that raises no eyebrows on any system.

The result: two separate spying tools running quietly inside normal Windows processes.

One belongs to the Gh0st RAT lineage, tracked under that name across multiple vendor reports and active for well over a decade. The second sits in the QuasarRAT and AsyncRAT family, open-source remote-access tools that criminal groups have repurposed for years. Both let the attacker run commands, copy files, watch the screen, and install further payloads. Our 1 July story on trojanized ScreenConnect installers documented a different campaign abusing AsyncRAT the same week, and on 6 July we reported a separate operation posing as India's Income Tax Department to target finance teams, suggesting the department's branding has become a reliable lure in circulation.

Each tool talks to its own command-and-control server, the server the attacker uses to issue instructions. Block one server and the second channel stays open. Cyderes described this as giving the attacker "redundant access even if one channel is blocked or detected."

Attribution warrants caution. Cyderes hasn't publicly linked this campaign to a named nation-state group. The tooling overlaps with both criminal and espionage clusters, and medium confidence is the ceiling on any state nexus without further infrastructure correlation.

Should you worry?

If you're an individual taxpayer in India, treat any unexpected email asking you to download a tax utility with real suspicion. Download software only from the official Income Tax Department website. If you opened something like this recently, ask an IT professional to check your machine.

Organisations with Indian employees or operations should watch for unusual activity from svchost.exe, unexpected new services, and any process hosting the .NET runtime when it normally wouldn't. The dual-server design is the detail worth sitting with: defenders have to find both implants, not just one.

© 2026 Threat Vectr