is that a scam?
United States India
United Kingdom Coming soon
Australia Coming soon
Canada Coming soon
EN
← Back to all scams
CRITICAL phishing Share

Email from "Income Tax Department" hides banking malware in its attachment

A spear-phishing email mimicking the Income Tax Dept carries a ZIP or PDF attachment with a banking trojan (Blackmoon) and remote-access tool. Opening it gives attackers your banking credentials and full device control.

Also known as: Blackmoon malware income tax India, fake ITR notice email malware, income tax compliance email scam, SyncFuture RAT income tax phishing

What to do right now

  1. 1 Do not open any attachment in an email claiming to be from the Income Tax Department — genuine ITD notices never come as ZIP email attachments
  2. 2 Verify any ITD notice at the official portal: https://www.incometax.gov.in
  3. 3 If you opened the attachment, disconnect from the internet immediately, run a full antivirus scan, and change all banking passwords from a separate clean device
  4. 4 Call your bank's fraud helpline immediately to freeze your net banking and UPI access
  5. 5 If you installed any 'support' or 'server' or 'refund app' or remote-access app at the scammer's request (AnyDesk, TeamViewer, Quick Support, etc.), run free SeraphSecure (https://www.seraphsecure.com) to detect and remove it.
  6. 6 Report at https://cybercrime.gov.in or call 1930 (national cyber helpline).

Was remote-access software installed?

If a scammer asked you to install AnyDesk, TeamViewer, Quick Support, or any remote-access app, your device may still be compromised.

Run SeraphSecure to detect and remove it →

Red flags

  • Income Tax Department sends official notices via the ITD portal (incometaxindiaefiling.gov.in) — never by email with attachments
  • The email domain is a lookalike (e.g., incometax-notice.gov.in.*, itd-compliance.*) — not the official @incometax.gov.in
  • A Document Identification Number (DIN) in the email looks plausible but cannot be verified on the ITD portal
  • The ZIP attachment contains both a PDF and an executable — the executable is the malware
  • After opening the attachment your antivirus may flag 'SyncFuture' or 'Blackmoon' processes

Sources

Share this with someone who might need it