Phishing in Disguise: How Attackers Deliver DcRAT via a Fake Tax Utility

Colleagues, I’d like to highlight a cyber incident.
I came across a campaign in which attackers send emails impersonating India’s Income Tax Department and disguise the attack as a tax-related notice.
Key points:
- victims are prompted to download a ZIP file containing an alleged offline filing utility;
- once launched, DLL sideloading triggers the malicious chain;
- the malware then establishes persistence via the MixedSvc service, uses anti-analysis techniques, and disables AMSI;
- the final payload is DcRAT, enabling data theft from the infected machine.
Why it matters: these attacks appear credible and target both financial and corporate users.
How do you protect employees from such lures?
#cybersecurity #phishing #malware #threatintel

