Cybercriminals are exploiting the income-tax return (ITR) filing season in India by sending forged tax department notices over WhatsApp and other messaging platforms, according to a report by Bengaluru-based cybersecurity firm CloudSek. TNN reported that the campaign comes at a time when millions of taxpayers are expecting messages related to refunds, notices and compliance deadlines, making them more likely to trust official-looking communications.
Forged notices and malware ZIPs target Android users
In the WhatsApp campaign documented by CloudSek, victims receive an “office memorandum” from an unknown or compromised account masquerading as the income tax department. The forged document features the government of India emblem, bilingual English and Hindi text, fabricated reference numbers and the name of a fake tax official to appear authentic, CloudSek reported. The notice falsely claims that discrepancies have been detected under Sec 271(1)(c) of the Income Tax Act and warns of prosecution under Sec 276C, giving recipients just 72 hours to respond.
Instead of including a web link, the message carries a ZIP attachment named “ITD.zip”, presented as tax documents. On Android devices, opening the file installs malware capable of accessing SMS messages, including banking one-time passwords (OTPs), contacts and keystrokes. The malware can also overlay fake login screens on banking and payment applications to capture usernames, passwords, and other sensitive information, CloudSek detailed.
Phishing sites clone the official e-filing portal
In a parallel campaign, fraudsters direct users to websites designed to closely resemble the official income-tax e-filing portal, according to CloudSek. These fake sites prompt users to enter PAN number, Aadhaar, passwords, OTPs, and bank account details, the firm reported. The report said attackers are using two primary methods: malware-laden WhatsApp attachments and phishing websites that closely mimic the official income-tax e-filing portal.
Two attack vectors compared
CloudSek’s report describes the two primary attack channels and the data each targets:
| Feature | WhatsApp malware campaign | Phishing portal campaign |
|---|---|---|
| Delivery channel | WhatsApp and other messaging platforms | Websites resembling the official e-filing portal |
| Lure | Forged “office memorandum” from the income tax department | Clone of the official income-tax e-filing portal |
| Document features | Govt of India emblem, bilingual text, fabricated reference numbers, fake official, Sec 271(1)(c), Sec 276C, 72-hour deadline | N/A |
| Payload | ZIP attachment “ITD.zip” installing Android malware | Fake login pages |
| Data targeted | SMS, banking OTPs, contacts, keystrokes, bank/payment app credentials | PAN number, Aadhaar, passwords, OTPs, bank account details |
The forged notice’s 72-hour response window and the threat of prosecution under Sec 276C are designed to pressure recipients into opening the ZIP attachment without verifying the source, according to the CloudSek report. The campaign’s use of a ZIP file rather than a web link demonstrates how attackers are adapting delivery mechanisms, the report indicated.
CloudSek’s findings were reported by TNN as assessees rushed to meet the I-T return filing deadline. The firm said the campaign relies on official-looking branding — government emblems, legal references and department names — to convince taxpayers that the messages are genuine.