In a concerning turn of events, cybersecurity researchers have uncovered a sophisticated cyber-espionage campaign specifically targeting Indian users. This nefarious operation masquerades as official communications from the Income Tax Department of India, using phishing emails to lure unsuspecting victims into a trap.
How the Attack Works
Victims who fall for this deception may find themselves downloading a malicious ZIP file, which contains a stealthy backdoor designed to operate undetected on their systems. The installation process initiates with an executable file named “Inspection Document Review.exe,” which sideloads a malicious DLL hidden within the archive. This DLL cleverly bypasses User Account Control (UAC) by disguising itself as a legitimate Windows process, ensuring that it remains hidden from users and security software.
Once installed, the backdoor provides cybercriminals with persistent access to the compromised machines. It enables continuous monitoring and data exfiltration, raising significant concerns about the security and privacy of affected individuals.
The Underlying Threat
At the heart of this campaign is a variant of the notorious banking trojan known as Blackmoon (also referred to as KRBanker). In addition, the attackers utilize a legitimate enterprise tool, SyncFuture TSM (Terminal Security Management), developed by Nanjing Zhongke Huasai Technology Co., Ltd., a Chinese technology company. This dual approach significantly enhances the attackers’ capabilities, allowing them to monitor user activities and steal sensitive information without detection.
What’s Inside the Malicious ZIP File?
The malicious ZIP file distributed through these fake tax notices contains five hidden files. It strategically deploys batch scripts that perform various harmful actions, such as:
- Creating custom directories and altering Access Control Lists (ACLs) to grant unauthorized permissions.
- Manipulating user permissions on Desktop folders.
- Executing cleanup and restoration operations to obscure traces of the attack.
Additionally, the executable named “MANC.exe” orchestrates services and maintains extensive logging, further empowering the attackers’ control over the compromised environment.
Evading Detection
The malware demonstrates a high level of sophistication by employing automated mouse simulation techniques. If it detects that Avast Free Antivirus is running, it cleverly navigates through the antivirus interface to add malicious files to the exclusion list, all while maintaining functionality. This allows it to remain undetected, showcasing the attackers’ acute awareness of cybersecurity measures.
Protect Yourself
To safeguard against this growing threat, it’s crucial to remain vigilant when opening emails, especially those claiming to be from government agencies. Always verify the sender’s address and avoid downloading attachments from unknown or suspicious sources.
Stay informed, and ensure that your antivirus software is up-to-date to help protect against these stealthy threats. Cybersecurity is everyone’s responsibility, and awareness is your first line of defense against potential breaches.

In summary, this cyber-espionage campaign exemplifies the tactics employed by modern cybercriminals to exploit trust and manipulate users. By safeguarding your digital environment and maintaining awareness, you can significantly reduce the risk of falling victim to such sophisticated attacks.

Tax Concept is a dedicated team of financial writers, legal analysts, and tax professionals committed to breaking down complex Indian corporate updates. From real-time GST amendments and crucial Income Tax judgements to EPFO schemes and corporate law updates, TaxConcept serves as a reliable, authoritative guide for chartered accountants, businesses, and everyday taxpayers seeking absolute compliance clarity.
