ಇದು ಮೋಸವೇ?
← ಎಲ್ಲಾ ಮೋಸಗಳಿಗೆ ಹಿಂತಿರುಗಿ
CRITICAL phishing ಹಂಚಿಕೊಳ್ಳಿ

"ಆದಾಯ ತೆರಿಗೆ ಇಲಾಖೆ" ಇಮೇಲ್ attachment ನಲ್ಲಿ ಬ್ಯಾಂಕಿಂಗ್ malware ಅಡಗಿದೆ

Income Tax Department ಎಂದು ನಟಿಸಿ ಕಳಿಸಿದ ಇಮೇಲ್‌ನ ZIP ಅಥವಾ PDF attachment ನಲ್ಲಿ banking trojan (Blackmoon) ಮತ್ತು remote access tool ಅಡಗಿರುತ್ತದೆ. attachment ತೆರೆದರೆ banking credentials ಮತ್ತು ಸಂಪೂರ್ಣ device ನಿಯಂತ್ರಣ ವಂಚಕನಿಗೆ ಹೋಗುತ್ತದೆ.

ಇತರ ಹೆಸರುಗಳು: Blackmoon malware income tax India, ನಕಲಿ ITR notice email malware, income tax compliance email ವಂಚನೆ, Gh0st RAT income tax phishing India, AsyncRAT ITR deadline malware, dual malware income tax email India

ಈಗ ಏನು ಮಾಡಬೇಕು

  1. 1 Income Tax Department ಇಮೇಲ್‌ನ ಯಾವ attachment ಅನ್ನೂ ತೆರೆಯಬೇಡಿ
  2. 2 ಅಧಿಕೃತ ITD notice ಕೇವಲ https://www.incometax.gov.in ನಲ್ಲಿ ಪರಿಶೀಲಿಸಿ
  3. 3 attachment ತೆರೆದಿದ್ದರೆ ತಕ್ಷಣ internet ಕಡಿತಗೊಳಿಸಿ, antivirus scan ಮಾಡಿ
  4. 4 ಬೇರೆ device ನಿಂದ banking passwords ಮತ್ತು UPI PIN ಬದಲಾಯಿಸಿ
  5. 5 If you installed any 'support' or 'server' or 'refund app' or remote-access app at the scammer's request (AnyDesk, TeamViewer, Quick Support, etc.), run free SeraphSecure (https://www.seraphsecure.com) to detect and remove it.
  6. 6 Report at https://cybercrime.gov.in or call 1930 (national cyber helpline).

ರಿಮೋಟ್ ಆಕ್ಸೆಸ್ ಸಾಫ್ಟ್‌ವೇರ್ ಇನ್‌ಸ್ಟಾಲ್ ಆಯಿತೇ?

ಯಾರಾದರೂ ಮೋಸಗಾರರು AnyDesk, TeamViewer, Quick Support ಅಥವಾ ಯಾವುದೇ ರಿಮೋಟ್ ಆಕ್ಸೆಸ್ ಅಪ್ಲಿಕೇಶನ್ ಇನ್‌ಸ್ಟಾಲ್ ಮಾಡಲು ಹೇಳಿದ್ದರೆ, ನಿಮ್ಮ ಸಾಧನ ಇನ್ನೂ ಅಪಾಯದಲ್ಲಿ ಇರಬಹುದು.

SeraphSecure ಚಲಾಯಿಸಿ — ಪತ್ತೆ ಮಾಡಿ ಮತ್ತು ತೆಗೆದುಹಾಕಿ →

ಎಚ್ಚರಿಕೆ ಸಂಕೇತಗಳು

  • Income Tax Department ಎಂದಿಗೂ ZIP attachment ಸಹಿತ ಇಮೇಲ್ ಕಳಿಸುವುದಿಲ್ಲ — ಅಧಿಕೃತ notices ITD portal ನಲ್ಲಿ ಇರುತ್ತವೆ
  • ಇಮೇಲ್ domain ನಕಲಿ ಇರುತ್ತದೆ (ಉದಾ. incometax-notice.gov.in.* ಅಥವಾ itd-compliance.*)
  • ಇಮೇಲ್‌ನಲ್ಲಿ DIN number ಕಾಣಿಸುತ್ತದೆ ಆದರೆ ITD portal ನಲ್ಲಿ verify ಆಗುವುದಿಲ್ಲ
  • ZIP ನಲ್ಲಿ PDF ಮತ್ತು executable (.exe) ಎರಡೂ ಇರುತ್ತವೆ — executable malware ಆಗಿದೆ

ತಿಳಿದ ರೂಪಾಂತರಗಳು

  • Gh0st RAT + AsyncRAT dual-malware (ಜುಲೈ 2026): ಇಮೇಲ್‌ಗಳು outstanding dues ಅಥವಾ ITR mismatch ಎಂದು July 31 deadline ಒತ್ತಡದೊಂದಿಗೆ ಬರುತ್ತವೆ. ZIP/ISO attachment six-stage loader ಹಾಕಿ Gh0st RAT (keylogging) ಮತ್ತು AsyncRAT (credential harvesting) ಏಕಕಾಲದಲ್ಲಿ deploy ಮಾಡುತ್ತದೆ. Telegram ನಲ್ಲಿ ಮಾರಾಟ ಆಗುವ builder kit ಅನ್ನು ಅನೇಕ attackers ಬಳಸುತ್ತಾರೆ.

    Last seen: 7/30/2026

  • Operation DragonReturn / DcRAT fake utility (June–July 2026): China-nexus actors spear-phishing emails ಕಳುಹಿಸುತ್ತಾರೆ, ITD official offline filing utility ಡೌನ್‌ಲೋಡ್ ಲಿಂಕ್ ಸಹ. Download ಮಾಡಿದ ZIP ನಿಂದ DLL sideloading chain DcRAT (Gh0st derivative) + AsyncRAT deploy ಮಾಡುತ್ತದೆ। Targets: taxpayers, CAs, corporate finance। May 18 ರಿಂದ active।

    Last seen: 8/15/2026

ಮೂಲಗಳು

ಇದು ಬೇಕಾಗಬಹುದಾದ ಯಾರಿಗಾದರೂ ಹಂಚಿಕೊಳ್ಳಿ

WhatsApp Email