Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft August 2026 Patch Tuesday fixes 394 flaws, including 3 zero-days
August 11, 2026
Critical Zoom Zero-Click Flaws Let Attackers Hijack User Devices
August 11, 2026
DEF CON Attendees Broadcast Fake Wi-Fi Network on Flight
August 11, 2026
Home/Threats/Attackers Infect Windows Systems With Fake Income Tax Assessment Pages
Threats

Attackers Infect Windows Systems With Fake Income Tax Assessment Pages

Key Takeaways A new, sophisticated phishing campaign, dubbed TAX#TRIDENT, is targeting Windows users in India with fake income tax assessment pages. The attack leverages social engineering to trick...

David kimber
David kimber
May 20, 2026 6 Min Read
83 0

Key Takeaways

  • A new, sophisticated phishing campaign, dubbed TAX#TRIDENT, is targeting Windows users in India with fake income tax assessment pages.
  • The attack leverages social engineering to trick victims into downloading malicious files disguised as official documents, leading to full system compromise.
  • TAX#TRIDENT employs three distinct infection chains, all initiating with a tax-themed lure but diverging in their delivery and payload, often abusing legitimate remote management software.
  • The threat is highly adaptable, rotating delivery methods and decoys, making traditional signature-based detection ineffective.

A new wave of malicious activity is targeting Windows users in India, employing highly convincing fake income tax assessment pages to distribute malware. This campaign, identified by researchers as TAX#TRIDENT, demonstrates remarkable adaptability in its delivery mechanisms while maintaining a consistent and urgent tax-related lure.

Table Of Content

  • Key Takeaways
  • How Fake Tax Pages Deliver Malware
  • When Signed Tools Become the Weapon
  • Indicators of Compromise (IoCs)
  • What You Should Do

Unlike attacks exploiting technical vulnerabilities, TAX#TRIDENT relies entirely on social engineering. Its success hinges on the victim’s belief that the downloaded file is a legitimate government notice, prompting them to execute what is, in reality, a sophisticated piece of malware capable of full system compromise.

The campaign’s use of tax notices is particularly effective, generating a sense of urgency that can compel individuals across various professional roles—including finance, legal, HR, and executive positions—to act without sufficient scrutiny.

According to a report by Securonix Threat Research, led by Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee, TAX#TRIDENT operates through three distinct infection chains. While each path begins with the same deceptive tax theme, they diverge in their execution, providing the attackers with flexibility to switch tactics if one method is detected or blocked.

A significant challenge in combating this campaign is its abuse of digitally signed, legitimate software rather than overtly malicious files. Two of the three attack branches ultimately deploy a signed remote management client called “ClientSetup,” granting attackers persistent access to the compromised system. The third path silently enrolls the victim’s device into a genuine ManageEngine UEMS agent, redirecting it to an attacker-controlled server. This technique allows the malware to bypass security tools that rely solely on file signatures for detection.

The TAX#TRIDENT campaign continues to evolve, constantly shifting its delivery routes, decoys, and final payloads, while keeping older methods active. This inherent adaptability makes it a persistent and challenging threat for defenders.

How Fake Tax Pages Deliver Malware

The initial infection path begins with a visit to a fraudulent Indian Income Tax website, such as zyisykm.shop. Upon clicking a download button, victims receive a ZIP archive named “Assessment Letter.zip.” This archive contains a signed Windows executable designed to install a full remote management client.

Intriguingly, the attacker embeds the command-and-control (C2) server address directly within the installer’s filename. During execution, the installer reads its own name to extract this value and configure local settings. Post-installation, the executable creates a hidden directory within a Windows system folder and drops a fake svchost.exe alongside legitimate-looking driver files named YtMiniFilter and ytdisk.

A second infection vector utilizes a VBScript file, “Assessment_Order.vbs,” distributed via multiple fake tax domains. This script silently executes, displays a decoy tax image to the user, and simultaneously installs the same ClientSetup payload in the background. Despite originating from different domains and configured with varied server values, both the first and second chain executables share an identical SHA256 hash, confirming they deploy the same core payload.

Defenders are advised against relying solely on domain or filename blocklists. More robust detection should focus on behavioral anomalies, such as filenames containing IP addresses, the creation of hidden directories under system folders, svchost.exe running from unusual locations, and outbound network traffic on ports 6671, 6681, and 6683.

When Signed Tools Become the Weapon

The third infection chain deviates significantly, abandoning the ClientSetup payload entirely. This path initiates from a PHP-looking URL, xhxz.info/download.php, which surprisingly returns VBScript instead of a web page. This script then stages subsequent files from Amazon S3 buckets.

One notable file, “uacMC.png,” is not an image but a script designed to silently lower User Account Control (UAC) settings. This action effectively removes elevation prompts, paving the way for the final payload to execute without user intervention.

The ultimate payload in this chain is a full ManageEngine UEMS agent, downloaded and installed discreetly without any visible user interface. A configuration file, DCAgentServerInfo.json, directs this legitimate agent to an attacker-controlled server at 202.61.160.201 on port 8383. This method effectively hijacks a trusted enterprise tool, transforming a signed and valid agent into a silent, persistent remote access channel for the attackers.

Securonix strongly advises users to avoid downloading files from unsolicited tax or penalty links, regardless of how official they appear. Security teams should implement monitoring for script engines executing files with web-style extensions, flag svchost.exe processes running from non-standard directories, and alert on UAC policy changes where “ConsentPromptBehaviorAdmin” is set to zero.

Effective detection strategies must prioritize behavioral signals over static indicators like file hashes, given the campaign’s continuous rotation of infrastructure while its core tactics remain consistent.

Indicators of Compromise (IoCs)

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Type Indicator Description
URL https://zyisykm[.]shop/ Fake Indian Income Tax assessment page (Chain 1 lure)
IP Address 149.104.24.197 Resolved IP for zyisykm[.]shop lure page
File Name Assessment Letter.zip Malicious ZIP archive delivered from lure page
File Name 45.119.55.66ClientSetup.exe Chain 1 ClientSetup installer; IP embedded in filename
SHA256 950AD7A33457A1A37A0797316CDD2FBAF9850F7165425274351D08B3C01ED2D8 Hash shared by both Chain 1 and Chain 2 ClientSetup executables
IP Address 45.119.55.66 Chain 1 C2 server; contacted on ports 6671, 6681, 6683
File Name Assessment_Order.vbs VBScript downloader used in Chain 2
URL https://gooomld[.]top/ Fake tax domain serving Assessment_Order.vbs
URL https://goolmor[.]cyou/ Fake tax domain serving Assessment_Order.vbs
URL https://fgsdol[.]icu/ Fake tax domain serving Assessment_Order.vbs
URL https://vsdnk[.]top/ Fake tax domain serving Assessment_Order.vbs
URL https://gooomoel[.]shop/ Fake tax domain serving Assessment_Order.vbs
URL https://tengxxi[.]com/216.250.104.166ClientSetup.exe Chain 2 payload download URL
File Name 216.250.104.166ClientSetup.exe Chain 2 ClientSetup installer; alternate IP in filename
IP Address 216.250.104.166 Chain 2 C2 server
URL https://xhxz[.]info/download.php Chain 3 PHP-named VBScript endpoint
URL https://sjdkjj23[.]s3.ap-southeast-1.amazonaws.com/uacMC.png S3-hosted fake PNG/VBScript UAC modifier
URL https://xijkwm2[.]s3.ap-southeast-1.amazonaws.com/1122.vbs S3-hosted Chain 3 VBScript stage
URL https://xijkwm2[.]s3.ap-southeast-1.amazonaws.com/8081.zip S3-hosted ManageEngine UEMS agent bundle
File Name uacMC.png VBScript disguised as image; lowers UAC ConsentPromptBehaviorAdmin to 0
File Name DCAgentServerInfo.json UEMS agent configuration pointing to attacker server
IP Address 202.61.160.201 Chain 3 attacker-controlled UEMS enrollment server
Network 202.61.160.201:8383 UEMS agent HTTPS communication port
Network 202.61.160.201:8027 UEMS recurring status/heartbeat channel
Directory C:WindowsSysWOW64msres Hidden client directory created by ClientSetup
Directory C:SystemUpdates Chain 2 VBScript staging directory
Directory C:UsersPublicDocumentsMSUpdate_* Chain 3 staging directory created by VBScript
File Name YTSysConfig.ini ClientSetup runtime configuration file
File Name YTSysConfig.ytf ClientSetup secondary configuration file
Service Name MANC Windows service created for ClientSetup persistence
Driver Name YtMiniFilter Driver installed by ClientSetup for deep system access
Driver Name ytdisk Driver installed by ClientSetup for file/disk monitoring

What You Should Do

  • Educate Users: Conduct regular training on phishing awareness, emphasizing the dangers of unsolicited emails, messages, or links related to tax assessments, penalties, or refunds.
  • Verify Sources: Instruct users to always verify the authenticity of tax-related communications directly with official government websites, never through embedded links or downloaded attachments.
  • Implement Email Security: Deploy robust email security solutions with advanced threat protection, sandboxing, and URL rewriting capabilities to detect and block malicious lures.
  • Enhance Endpoint Detection: Utilize Endpoint Detection and Response (EDR) solutions capable of monitoring behavioral anomalies, such as scripts executing from unusual locations, hidden directory creation, and unexpected UAC policy changes.
  • Monitor Network Traffic: Implement network segmentation and monitor outbound traffic for connections to suspicious IP addresses and non-standard ports (e.g., 6671, 6681, 6683, 8383) that could indicate C2 communication.
  • Disable Unnecessary Script Execution: Configure Group Policies to restrict or disable VBScript execution where it is not essential for business operations.
  • Review UAC Settings: Regularly audit and enforce UAC policies to prevent unauthorized modification of security settings, specifically ensuring that ConsentPromptBehaviorAdmin is not set to zero.
  • Update Security Software: Ensure all antivirus, anti-malware, and security software are kept up-to-date with the latest definitions and behavioral detection capabilities.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwareSecurityThreatVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Void Botnet Leverages Ethereum Smart Contracts for Resilient C2

Next Post

Gremlin Stealer Hides C2 URLs and Paths in Encrypted Sections

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
LLM API Vulnerability Exposes AI Model Reasoning, Poses Data Risk
August 11, 2026
Critical SAP Vulnerabilities Allow Code Injection, Memory Corruption
August 11, 2026
Critical Ivanti Endpoint Manager CVEs Let Remote Attackers Crash Agent Service
August 11, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us