is that a scam?
← Back to all scams
CRITICAL phishing Share

Email from "Income Tax Department" hides banking malware in its attachment

A spear-phishing email mimicking the Income Tax Dept carries a ZIP or PDF attachment with a banking trojan (Blackmoon) and remote-access tool. Opening it gives attackers your banking credentials and full device control.

Also known as: Blackmoon malware income tax India, fake ITR notice email malware, income tax compliance email scam, SyncFuture RAT income tax phishing, Gh0st RAT income tax phishing India, AsyncRAT ITR deadline malware, dual malware income tax email India

What to do right now

  1. 1 Do not open any attachment in an email claiming to be from the Income Tax Department — genuine ITD notices never come as ZIP email attachments
  2. 2 Verify any ITD notice at the official portal: https://www.incometax.gov.in
  3. 3 If you opened the attachment, disconnect from the internet immediately, run a full antivirus scan, and change all banking passwords from a separate clean device
  4. 4 Call your bank's fraud helpline immediately to freeze your net banking and UPI access
  5. 5 If you installed any 'support' or 'server' or 'refund app' or remote-access app at the scammer's request (AnyDesk, TeamViewer, Quick Support, etc.), run free SeraphSecure (https://www.seraphsecure.com) to detect and remove it.
  6. 6 Report at https://cybercrime.gov.in or call 1930 (national cyber helpline).

Was remote-access software installed?

If a scammer asked you to install AnyDesk, TeamViewer, Quick Support, or any remote-access app, your device may still be compromised.

Run SeraphSecure to detect and remove it →

Red flags

  • Income Tax Department sends official notices via the ITD portal (incometaxindiaefiling.gov.in) — never by email with attachments
  • The email domain is a lookalike (e.g., incometax-notice.gov.in.*, itd-compliance.*) — not the official @incometax.gov.in
  • A Document Identification Number (DIN) in the email looks plausible but cannot be verified on the ITD portal
  • The ZIP attachment contains both a PDF and an executable — the executable is the malware
  • After opening the attachment your antivirus may flag 'SyncFuture' or 'Blackmoon' processes

Known variants

  • Gh0st RAT + AsyncRAT dual-malware (July 2026): emails cite outstanding dues or ITR mismatch tied to the July 31 deadline. ZIP/ISO attachment drops a six-stage loader deploying Gh0st RAT (keylogging, screen capture) and AsyncRAT (credential harvesting) simultaneously. Multiple actors shared the same builder kit sold on Telegram.

    Last seen: 7/30/2026

  • Operation DragonReturn / DcRAT fake utility (Jun–Jul 2026): China-nexus spear-phishing links to a fake ITD site; victims download a ZIP disguised as the official offline filing utility; DLL sideloading deploys DcRAT + AsyncRAT. Targets taxpayers and CAs. Active since May 2026.

    Last seen: 8/15/2026

  • WhatsApp delivery (August 2026): fake ITD notice via WhatsApp includes a bilingual penalty notice (Section 271/276C) with 72-hour deadline and ITD.zip. On Android the ZIP installs an APK intercepting banking OTPs and showing fake bank overlays; on Windows it drops ITD_Tax_Notice.exe. Timed to hit taxpayers awaiting refunds post July 31.

    Last seen: 8/15/2026

Sources

Share this with someone who might need it