{"id":206733,"date":"2026-01-26T12:01:00","date_gmt":"2026-01-26T17:01:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/01\/26\/indian-users-targeted-in-tax-phishing-campaign-delivering-blackmoon-malware\/"},"modified":"2026-01-26T15:45:07","modified_gmt":"2026-01-26T20:45:07","slug":"indian-users-targeted-in-tax-phishing-campaign-delivering-blackmoon-malware","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/01\/26\/indian-users-targeted-in-tax-phishing-campaign-delivering-blackmoon-malware\/","title":{"rendered":"Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/01\/indian-users-targeted-in-tax-phishing.html\">Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/01\/indian-users-targeted-in-tax-phishing.html\">https:\/\/thehackernews.com\/2026\/01\/indian-users-targeted-in-tax-phishing.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-01-26 12:01:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">Jan 26, 2026<\/span><\/span><span class=\"p-tags\">Cyber Espionage \/ Malware<\/span><\/p>\n<p>Cybersecurity researchers have discovered an ongoing campaign that&#8217;s targeting Indian users with a multi-stage backdoor as part of a suspected cyber espionage campaign.<\/p>\n<p>The activity, per the eSentire Threat Response Unit (TRU), involves using phishing emails impersonating the Income Tax Department of India to trick victims into downloading a malicious archive, ultimately granting the threat actors persistent access to their machines for continuous monitoring and data exfiltration.<\/p>\n<p>The end goal of the sophisticated attack is to deploy a variant of a known banking trojan called Blackmoon (aka KRBanker) and a legitimate enterprise tool called SyncFuture TSM (Terminal Security Management) that&#8217;s developed by Nanjing Zhongke Huasai Technology Co., Ltd, a Chinese company. The campaign has not been attributed to any known threat actor or group.<\/p>\n<p><img decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgqlhh16hjmE7NRyQeAR2_sLZ1uDwyQH2jkPHmDTAtveTHoIjCrfmK6JLqlZuNKOPG1RGLtwJk-ZJDwQiV-McwmzAUu1iOSwwMjs_tqI1KjcL_tCvc0M2XuKBPfJ1RXpKxnx-eGdWwM0wlNDnUYHvXr-1LZk2zRmDNLIEbYGalGQJsd6QwC0pyCrLavN0fz\/s728-e100\/threatlocker-inside-d.png\" width=\"729\" height=\"91\"\/><\/p>\n<p>&#8220;While marketed as a legitimate enterprise tool, it is repurposed in this campaign as a powerful, all-in-one espionage framework,&#8221; eSentire said. &#8220;By deploying this system as their final payload, the threat actors establish resilient persistence and gain a rich feature set to monitor victim activity and centrally manage the theft of sensitive information.&#8221;<\/p>\n<p>The ZIP file distributed through the fake tax penalty notices contains five different files, all of which are hidden except for an executable (&#8220;Inspection Document Review.exe&#8221;) that&#8217;s used to sideload a malicious DLL present in the archive. The DLL, for its part, implements checks to detect debugger-induced delays and contacts an external server to fetch the next-stage payload.<\/p>\n<p>The downloaded shellcode then uses a COM-based technique to bypass the User Account Control (UAC) prompt to gain administrative privileges. It also modifies its own Process Environment Block (PEB) to masquerade as the legitimate Windows &#8220;explorer.exe&#8221; process to fly under the radar.<\/p>\n<p>On top of that, it retrieves the next stage &#8220;180.exe&#8221; from&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/01\/indian-users-targeted-in-tax-phishing.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Indian Users Targeted in Tax Phishing Campaign Delivering Blackmoon Malware https:\/\/thehackernews.com\/2026\/01\/indian-users-targeted-in-tax-phishing.html Publish Date: 2026-01-26 12:01:00&#8230;<\/p>\n","protected":false},"author":1,"featured_media":206734,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhvLevjTVc4Wtdleam1414FTgJVVKT9y6jsB2W08-6gbA8HuiacVQ-4WJPpaZoMSxTO2itbkV627HlV5O-9dmliOKbW_xQfrkkhe_BpV_yawvBOWxP0flMx0D7SsnhvKgpLEZDQfJfLl8UUj_OqDiVBwmMfXVETSHRKtaKD2L1PQaOqQkrchj14hbCpIHWs\/s1700-e365\/itd.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,32,25,34],"class_list":["post-206733","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-malware","tag-phishing","tag-threat-actor"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/206733"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=206733"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/206733\/revisions"}],"predecessor-version":[{"id":206735,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/206733\/revisions\/206735"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/206734"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=206733"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=206733"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=206733"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}