Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware

As part of a suspected cyber espionage campaign, cybersecurity researchers have found an ongoing campaign that targets Indian consumers with a multi-stage backdoor.

According to the eSentire Threat Response Unit (TRU), the activity entails tricking victims into downloading a malicious archive through phishing emails posing as the Income Tax Department of India. This gives the threat actors permanent access to the victims’ computers for ongoing monitoring and data exfiltration.

The complex attack’s ultimate objective is to use a genuine enterprise solution called SyncFuture TSM (Terminal Security Management), created by the Chinese company Nanjing Zhongke Huasai Technology Co., Ltd., and a variation of the well-known banking trojan Blackmoon (also known as KRBanker). No known threat actor or group has been linked to the initiative.

According to eSentire, it is repurposed in this campaign as a potent, all-in-one espionage framework despite being presented read more about Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *