
Tax and SSA Phish Push Cruciferra Malware Loader
Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The…
A real phishing campaign targeted Indian businesses and individual taxpayers by impersonating government departments and sending emails that look like official GST tax notices. The goal was to trick recipients into opening convincing “refund/compliance” documents that install Remcos RAT to steal sensitive information.
This campaign targeted Indian businesses and individual taxpayers by impersonating government tax departments. The attackers sent emails disguised as official notifications covering taxation, refunds, compliance requirements, and regulatory matters, all built around Goods and Services Tax (GST) themes that are highly relevant to the target audience. The stated end goal of the campaign was to deploy Remcos RAT, a remote access trojan, and steal sensitive information from infected systems.
The campaign relied on the borrowed credibility of government institutions to increase the likelihood that recipients would open malicious content. Because GST-related correspondence is a routine part of business operations in India, recipients had less reason to be suspicious of an email that appeared to come from a tax authority. The attackers also employed convincing documents and filenames that closely resembled official GST notifications, making it difficult for recipients to distinguish malicious content from legitimate government correspondence. This combination of a trusted theme and polished presentation increased the odds of successful infection.
The campaign's targeting reflects who typically handles GST-related paperwork: finance, accounting, and tax/compliance staff, executive assistants, and small or medium business owners. Any employee who regularly deals with invoices, taxes, or regulatory correspondence was a plausible target, since these roles are conditioned to expect and act on official-looking tax notices.
Organizations and individuals can reduce risk by treating unexpected tax refund or compliance emails as high-risk, even when they look official, and verifying them through a trusted, independent channel rather than replying to or clicking within the email itself. Extra caution with attachments and official-looking filenames is warranted, since attackers depend on convincing documents to prompt recipients to open them. Because the end goal in this case involves data theft via Remcos RAT, any suspected infection should be reported quickly to limit potential damage. Training staff who routinely handle tax, invoice, or regulatory emails to recognize these patterns can meaningfully reduce the chance that this type of campaign succeeds.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is a phishing campaign that impersonates Indian government tax departments, sending emails disguised as official GST refund or compliance notices to trick recipients into opening malicious attachments.
The campaign's stated end goal is to deploy Remcos RAT, a remote access trojan used to steal sensitive information from infected systems.
The campaign targets Indian businesses across multiple sectors and individual taxpayers, with particular risk to finance, accounting, tax/compliance staff, and small business owners who handle invoices or regulatory emails.
Attackers impersonate legitimate government departments and use convincing documents and filenames that closely resemble official GST notifications, making them hard to distinguish from real correspondence.
You get an email: “Subject: GST Refund / Compliance Notice, Action Required.” Looks like it’s from a tax department in India. This isn’t about helping you file GST. It’s a malware campaign abusing government credibility to drop Remcos RAT on Indian businesses and taxpayers. Here’s the trick: the email impersonates a GST authority, but the sender domain isn’t a real .gov.in address, and the ‘official’ attachment asks you to enable content or run steps no real tax notice needs. If you get an unexpected GST refund or compliance email, don’t open the attachment, go to the official GST portal or your tax advisor and verify it there first.

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The…

Kaspersky reports an active malware campaign (“OkoBot”) that tricks people into running malicious scripts via a ClickFix-style prompt or by downloading a fake…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…

Researchers at Unit 42 reported a real espionage campaign targeting organizations using Zimbra webmail, including government, defense, transportation and…

Proofpoint observed real phishing campaigns using government-themed lures to trick people into downloading ZIP files that install malware. The campaigns used a…