VMTech
Discuss a project

Phishing in Disguise: How Attackers Deliver DcRAT via a Fake Tax Utility

Phishing in Disguise: How Attackers Deliver DcRAT via a Fake Tax Utility

Colleagues, I’d like to highlight a cyber incident.

I came across a campaign in which attackers send emails impersonating India’s Income Tax Department and disguise the attack as a tax-related notice.

Key points:
- victims are prompted to download a ZIP file containing an alleged offline filing utility;
- once launched, DLL sideloading triggers the malicious chain;
- the malware then establishes persistence via the MixedSvc service, uses anti-analysis techniques, and disables AMSI;
- the final payload is DcRAT, enabling data theft from the infected machine.

Why it matters: these attacks appear credible and target both financial and corporate users.

How do you protect employees from such lures?
#cybersecurity #phishing #malware #threatintel

Open analytics
On the site 4 views
min read 1 06.07.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

Phishing in Disguise: How Attackers Deliver DcRAT via a Fake Tax Utility

Open the post on Instagram ↗