GST-Themed Phishing Hits India With Remcos RAT

The Hacker News · Medium sophistication
Last updated July 30, 2026

A real phishing campaign targeted Indian businesses and individual taxpayers by impersonating government departments and sending emails that look like official GST tax notices. The goal was to trick recipients into opening convincing “refund/compliance” documents that install Remcos RAT to steal sensitive information.

How the Attack Worked

This campaign targeted Indian businesses and individual taxpayers by impersonating government tax departments. The attackers sent emails disguised as official notifications covering taxation, refunds, compliance requirements, and regulatory matters, all built around Goods and Services Tax (GST) themes that are highly relevant to the target audience. The stated end goal of the campaign was to deploy Remcos RAT, a remote access trojan, and steal sensitive information from infected systems.

Why It Succeeded

The campaign relied on the borrowed credibility of government institutions to increase the likelihood that recipients would open malicious content. Because GST-related correspondence is a routine part of business operations in India, recipients had less reason to be suspicious of an email that appeared to come from a tax authority. The attackers also employed convincing documents and filenames that closely resembled official GST notifications, making it difficult for recipients to distinguish malicious content from legitimate government correspondence. This combination of a trusted theme and polished presentation increased the odds of successful infection.

Who Was at Risk

The campaign's targeting reflects who typically handles GST-related paperwork: finance, accounting, and tax/compliance staff, executive assistants, and small or medium business owners. Any employee who regularly deals with invoices, taxes, or regulatory correspondence was a plausible target, since these roles are conditioned to expect and act on official-looking tax notices.

What to Watch For

  • Unexpected tax refund or compliance notices that create urgency to act quickly
  • Sender email domains that do not match a known official government channel
  • Attachments that prompt you to enable content or follow unusual steps not typical of tax correspondence
  • Filenames and document formatting designed to closely mimic real GST notifications

How to Build Resistance

Organizations and individuals can reduce risk by treating unexpected tax refund or compliance emails as high-risk, even when they look official, and verifying them through a trusted, independent channel rather than replying to or clicking within the email itself. Extra caution with attachments and official-looking filenames is warranted, since attackers depend on convincing documents to prompt recipients to open them. Because the end goal in this case involves data theft via Remcos RAT, any suspected infection should be reported quickly to limit potential damage. Training staff who routinely handle tax, invoice, or regulatory emails to recognize these patterns can meaningfully reduce the chance that this type of campaign succeeds.

Key findings

  • A malware campaign used GST tax-related themes to increase trust and open rates among Indian recipients.
  • Attackers impersonated government departments and sent emails disguised as official tax notifications (refunds, compliance, regulatory matters).
  • The stated end goal of the campaign was to deploy Remcos RAT and steal sensitive information.

Who’s being targeted

  • Commonly targeted roles: Finance, Accounting, Tax/Compliance, Executive assistants, Small/medium business staff, Any staff who handle invoices, taxes, or regulatory emails.
  • Affected industries: Indian businesses (multiple sectors), Individual taxpayers.
  • Attack channels: email.
  • Impersonated: Government tax department / GST authority.

Red flags to watch for

  • Unexpected tax/refund notice with urgency to act
  • Sender domain/email doesn’t match a known official government channel
  • Attachment prompts enabling content or running steps that aren’t normal for tax notices
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the GST-themed phishing campaign?

It is a phishing campaign that impersonates Indian government tax departments, sending emails disguised as official GST refund or compliance notices to trick recipients into opening malicious attachments.

What malware does this campaign deliver?

The campaign's stated end goal is to deploy Remcos RAT, a remote access trojan used to steal sensitive information from infected systems.

Who is being targeted by this campaign?

The campaign targets Indian businesses across multiple sectors and individual taxpayers, with particular risk to finance, accounting, tax/compliance staff, and small business owners who handle invoices or regulatory emails.

What makes these phishing emails convincing?

Attackers impersonate legitimate government departments and use convincing documents and filenames that closely resemble official GST notifications, making them hard to distinguish from real correspondence.

Read the video transcript

You get an email: “Subject: GST Refund / Compliance Notice, Action Required.” Looks like it’s from a tax department in India. This isn’t about helping you file GST. It’s a malware campaign abusing government credibility to drop Remcos RAT on Indian businesses and taxpayers. Here’s the trick: the email impersonates a GST authority, but the sender domain isn’t a real .gov.in address, and the ‘official’ attachment asks you to enable content or run steps no real tax notice needs. If you get an unexpected GST refund or compliance email, don’t open the attachment, go to the official GST portal or your tax advisor and verify it there first.

Similar attacks

Fake Job Offers Spread Lazarus Zero-Day Attack

Fake Job Offers Spread Lazarus Zero-Day Attack

Researchers describe a real, ongoing Lazarus-linked campaign where targets are lured with attractive job offers and tricked into downloading a PDF viewer and “job description” documents. Opening the files installs backdoors and, in at least one wave, attackers used a Windows zero-day to gain deep…

August 11, 2026
Phishing PDF Drops Malware Via Fake Edge Loader

Phishing PDF Drops Malware Via Fake Edge Loader

Researchers describe BraZetsu, a Windows malware framework used by an initial-access broker to turn infected PCs into "access for sale" on a criminal marketplace. While the malware itself is technical, the article includes real-world delivery details pointing to phishing: victims are tricked into…

September 3, 2026
Fake Freelancer Accounts Pushed Malicious Excel Macros

Fake Freelancer Accounts Pushed Malicious Excel Macros

U.S. prosecutors say a Russian national used hundreds of fake accounts on a freelance platform to send Excel files that tricked users into enabling macros, which then downloaded remote-control malware. The campaign targeted tens of thousands of users and led to thousands of infections, enabling…

September 2, 2026
APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

Researchers report real-world campaigns targeting European government and diplomatic organizations using diplomatic-themed Microsoft Word documents. Victims are prompted to click “Enable Content,” which runs malicious macros that install the HOOKEDGE backdoor and connect to webhook-based…

August 28, 2026
Voucher Lure Drops RAT via FTP Banner Tricks

Voucher Lure Drops RAT via FTP Banner Tricks

Researchers reported a real malware campaign where attackers use Spanish-language “voucher claim” messages to trick people into running a Windows Shortcut file. After the user clicks it, the malware pulls commands from an FTP server’s welcome banner and continues downloading additional payloads,…

August 25, 2026
APT42 Lures Targets With Podcast Invites

APT42 Lures Targets With Podcast Invites

Researchers report Iranian-linked APT groups using legitimate cloud services to hide command-and-control traffic, and separately running spear-phishing campaigns. In the phishing cases, attackers used credible “podcast” or “interview invitation” themes to persuade targets to open a Windows shortcut…

August 17, 2026