Malware Found Hiding in Fake Income Tax Department Emails, CERT-in Warns

The malware campaign is said to be active since September 12.

Advertisement
By Indo-Asian News Service | Updated: 23 September 2019 18:03 IST
Highlights
  • A phishing, malware campaign is active since September 12: CERT-In
  • Two variants of the latest malware emails have been observed
  • First has an attachment with extension “.img”, second has ".pif”

An information stealing computer malware, masking as a message from the Income Tax Department, has been found prowling in the Indian cyberspace, a federal cyber-security agency has warned in a recent advisory.

"A phishing and malware campaign is active since at least September 12 and is targeting individuals as well as financial organisations. The campaign involves fake emails purporting to be sent from Indian Income Tax Department," the CERT-In said its latest advisory accessed by PTI.

Indian Computer Emergency Response Team (CERT-In) is the national agency to combat hacking, phishing incidents, and to fortify security-related defences of the Indian Internet domain. While phishing denotes to a category of cybercrime where a person's personal vital information like banking, credit card details and passwords are stolen, malware is an e-virus.

Advertisement

A senior tax official said fraud links faking the I-T department are often used by fraudsters as people are very concerned and serious about their tax filing, refunds and other businesses with the department.

Advertisement

"It is very important to guard against any malicious email that talks about your I-T records or banking issues. The department has run many awareness series to educate people and taxpayers against these frauds," the official said.

The advisory said at least two variants of the latest malware emails have been observed. First variant includes an attachment with extension “.img” which contains a malicious “.pif” file while the second variant lures the users to download a malicious ".pif” file hosted on a sharepoint page via a link of fraudulent domain incometaxindia[.]info, it said.

Advertisement

This domain, it said, has now been disabled. "The malware samples add persistence by modifying the Windows registry and have been observed to have information stealing capabilities," it said.

It issued some samples of fraud emails being sent with subject line stating: “Important: Income Tax Outstanding Statements A.Y 2017-2018”; Income Tax Statement XML PAN XXX895X.pif; Income Tax Statment XML.img; Income Tax Statement XXX8957X.pif among others.

Advertisement

The agency also suggested some counter-measures: Do not to open documents from untrusted sources and should disable running macros in MS Office by default; don't open attachments in unsolicited e-mails, even if they come from people in your contact lists and never click on a URL contained in an unsolicited e-mail, even if the link seems benign, it said.

In cases of genuine URLs, close the e-mail and go to the organisation's website directly through browser, the Cert-In said.

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement
Popular Mobile Brands
  1. OnePlus 15T Details Revealed; New Telephoto Lens, Bigger Battery Confirmed
  2. Samsung 'Holi Hai' Sale Brings Offers on Bespoke AI Appliances
  3. Here's When the Oppo Find X9 Ultra Will Be Launched Globally
  4. Nothing Phone 4a Will Go on Sale in Bengaluru at a Drop Event on This Date
  5. iQOO Z11x 5G Will Launch in India on This Date
  6. Here's When the Oppo K14 5G Will Launch in India: See Expected Specs
  1. Capcom Spotlight Livestream Announced for This Week; Will Feature Pragmata, Mega Man: Dual Override and More
  2. Tanvi The Great Now Streaming on Prime Video: An Inspiring Autistic Hero’s Journey
  3. Aspirants Season 3 OTT Release Date Announced: When and Where to Watch it Online?
  4. Samsung Announces ‘Holi Hai’ Sale With Cashback on Bespoke AI Appliances
  5. Kiss of the Spider Woman OTT Release Date: Know When and Where to Watch it Online
  6. Vanchana OTT Release: When and Where to Watch the Courtroom Drama
  7. Xiaomi 18, Xiaomi 18 Pro, Xiaomi 18 Pro Max Early Leak Reveals Rear Camera Details
  8. Meta AI Reportedly Testing Personalised Shopping Recommendations to Compete With ChatGPT, Gemini
  9. Oppo Find N6 Reportedly Appears at MWC 2026; Company Confirms March Launch in China
  10. Resident Evil Requiem Becomes Highest User Rated Game of All Time on Metacritic
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.