GST-Themed Phishing Hits India With Remcos RAT

The Hacker News · Medium sophistication
Last updated July 30, 2026

A real phishing campaign targeted Indian businesses and individual taxpayers by impersonating government departments and sending emails that look like official GST tax notices. The goal was to trick recipients into opening convincing “refund/compliance” documents that install Remcos RAT to steal sensitive information.

How the Attack Worked

This campaign targeted Indian businesses and individual taxpayers by impersonating government tax departments. The attackers sent emails disguised as official notifications covering taxation, refunds, compliance requirements, and regulatory matters, all built around Goods and Services Tax (GST) themes that are highly relevant to the target audience. The stated end goal of the campaign was to deploy Remcos RAT, a remote access trojan, and steal sensitive information from infected systems.

Why It Succeeded

The campaign relied on the borrowed credibility of government institutions to increase the likelihood that recipients would open malicious content. Because GST-related correspondence is a routine part of business operations in India, recipients had less reason to be suspicious of an email that appeared to come from a tax authority. The attackers also employed convincing documents and filenames that closely resembled official GST notifications, making it difficult for recipients to distinguish malicious content from legitimate government correspondence. This combination of a trusted theme and polished presentation increased the odds of successful infection.

Who Was at Risk

The campaign's targeting reflects who typically handles GST-related paperwork: finance, accounting, and tax/compliance staff, executive assistants, and small or medium business owners. Any employee who regularly deals with invoices, taxes, or regulatory correspondence was a plausible target, since these roles are conditioned to expect and act on official-looking tax notices.

What to Watch For

  • Unexpected tax refund or compliance notices that create urgency to act quickly
  • Sender email domains that do not match a known official government channel
  • Attachments that prompt you to enable content or follow unusual steps not typical of tax correspondence
  • Filenames and document formatting designed to closely mimic real GST notifications

How to Build Resistance

Organizations and individuals can reduce risk by treating unexpected tax refund or compliance emails as high-risk, even when they look official, and verifying them through a trusted, independent channel rather than replying to or clicking within the email itself. Extra caution with attachments and official-looking filenames is warranted, since attackers depend on convincing documents to prompt recipients to open them. Because the end goal in this case involves data theft via Remcos RAT, any suspected infection should be reported quickly to limit potential damage. Training staff who routinely handle tax, invoice, or regulatory emails to recognize these patterns can meaningfully reduce the chance that this type of campaign succeeds.

Key findings

  • A malware campaign used GST tax-related themes to increase trust and open rates among Indian recipients.
  • Attackers impersonated government departments and sent emails disguised as official tax notifications (refunds, compliance, regulatory matters).
  • The stated end goal of the campaign was to deploy Remcos RAT and steal sensitive information.

Who’s being targeted

  • Commonly targeted roles: Finance, Accounting, Tax/Compliance, Executive assistants, Small/medium business staff, Any staff who handle invoices, taxes, or regulatory emails.
  • Affected industries: Indian businesses (multiple sectors), Individual taxpayers.
  • Attack channels: email.
  • Impersonated: Government tax department / GST authority.

Red flags to watch for

  • Unexpected tax/refund notice with urgency to act
  • Sender domain/email doesn’t match a known official government channel
  • Attachment prompts enabling content or running steps that aren’t normal for tax notices
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the GST-themed phishing campaign?

It is a phishing campaign that impersonates Indian government tax departments, sending emails disguised as official GST refund or compliance notices to trick recipients into opening malicious attachments.

What malware does this campaign deliver?

The campaign's stated end goal is to deploy Remcos RAT, a remote access trojan used to steal sensitive information from infected systems.

Who is being targeted by this campaign?

The campaign targets Indian businesses across multiple sectors and individual taxpayers, with particular risk to finance, accounting, tax/compliance staff, and small business owners who handle invoices or regulatory emails.

What makes these phishing emails convincing?

Attackers impersonate legitimate government departments and use convincing documents and filenames that closely resemble official GST notifications, making them hard to distinguish from real correspondence.

Read the video transcript

You get an email: “Subject: GST Refund / Compliance Notice, Action Required.” Looks like it’s from a tax department in India. This isn’t about helping you file GST. It’s a malware campaign abusing government credibility to drop Remcos RAT on Indian businesses and taxpayers. Here’s the trick: the email impersonates a GST authority, but the sender domain isn’t a real .gov.in address, and the ‘official’ attachment asks you to enable content or run steps no real tax notice needs. If you get an unexpected GST refund or compliance email, don’t open the attachment, go to the official GST portal or your tax advisor and verify it there first.

Similar attacks