Criminals Impersonating India's Income Tax Department to Deliver Malware: Symantec

Advertisement
By Press Trust of India | Updated: 22 January 2016 11:50 IST
Cybercriminals are targetting India, US and other countries with fraudulent "tax deduction" emails to steal information, security software firm Symantec said.

"During the last 3 months, Symantec has observed malicious emails claiming to be from India's Income Tax Department. The report shows 43 percent of these scam emails were delivered in India, followed by the US (20 percent), and the UK (14 percent)," Symantec Senior Security Response Manager Satnam Narang told PTI.

He added that there have been at least two types of emails in circulation - one that claims that thousands of rupees have been deducted from the recipient's bank account as a tax payment and the other copies the template of an actual intimation sent by the IT-Department.

Narang said the activity could grow further towards the closing of the financial year as people file their income and other taxes.

Advertisement

"While each email differs in its template, the goal is the same: to infect computers with an information-stealing Trojan that logs keystrokes. It also collects system information like titles of open windows and the operating system version that is sent back to attacker command and control server," he said.

The mails stating that money has been deducted contain an attached file that claim to be a receipt for the payment.

The alleged receipts are ZIP files that contain information-stealing malware that Symantec detects as Infostealer.Donx, he said.

Advertisement

On the other hand, the authentic looking mail with the Personal Account Number (PAN) (used to identify taxpayers in India) contains an attached ZIP file that is not password-protected.

"Contrary to what the email claims, the ZIP file does not contain a PDF. Instead, it contains another information-stealing Trojan that Symantec detects as Trojan.Gen," Narang said.

Advertisement

He added that the attackers spoof the domain for email addresses belonging to the Income Tax Department of India in an effort to make the emails look more convincing.

"In India, the IT-Department does send intimation emails to taxpayers. While these emails include attachments, they are password-protected using the taxpayers' PAN and date of birth/date of incorporation. This is unique to each entity and adds credibility that the source of the email is the IT Department," he said.

Advertisement

Narang added that one should avoid opening suspicious looking mails and report the email to Indian Computer Emergency Response Team (CERT-In).

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy S26 Series Launch Date Surfaces Ahead of Unpacked Event
  2. Here's How Much the Motorola Signature Could Cost in India
  3. Realme Neo 8 Pricing and Memory Configurations Leaked Ahead of Launch
  4. iPhone 18 Could Launch With Brighter Display, BOE May Lose Supplier Role
  5. OnePlus Nord 6 Arrives on Geekbench With These Key Specifications
  6. Best Laser Printers with Scanners That You Can Buy in India Right Now
  7. iPhone 18 Pro Series Expected to Debut With Dynamic Island, Tipster Claims
  8. Apple Pay Could Soon Be Available in India With Tap-to-Pay Support: Report
  9. Ram Charan's Peddi OTT Release Confirmed: What You Need to Know
  1. Google Pixel 10a Spotted With Familiar Design in Leaked Renders
  2. iPhone 18 Tipped to Launch With Brighter Display, BOE May Lose Supplier Role
  3. OnePlus Nord 6 Key Specifications Including Snapdragon 8s Gen 4 SoC Revealed via Geekbench Listing
  4. iQOO 15 Ultra Design and Colourways Revealed Ahead of Launch in China
  5. Samsung Galaxy S26 Launch Date, Pre-Order Timeline Tipped Ahead of Galaxy Unpacked Next Month
  6. Shambala Now Streaming Online: What You Need to Know About Aadi Saikumar Starrer Movie
  7. Deepinder Goyal to Step Down as Eternal CEO; Blinkit’s Albinder Dhindsa Named Successor
  8. Microsoft CEO Satya Nadella Says AI’s Real Test Is Whether It Reaches Beyond Big Tech: Report
  9. Meta's New AI Team Delivered First Key Models Internally This Month, CTO Says
  10. Apple Pay Reportedly Likely to Launch in India Soon; iPhone Maker Said to Be in Talks With Card Networks
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.