Operation TaxShadow: Multi-Region Tax Phishing & In-Memory Malware Campaign

June 5, 2026, 6:41 a.m.

Description

A sophisticated multi-stage malware campaign targets victims through tax-themed phishing emails impersonating Indian and Japanese government authorities. The operation leverages social engineering, fraudulent tax notifications, and trusted third-party email delivery services to distribute ZIP archives containing three staged payloads. The malware implements advanced evasion techniques including DLL Search Order Hijacking, API hooking, token manipulation, Mersenne Twister-based execution logic, COM callback execution, mutated RC4 encryption, and reflective PE loading. Execution occurs primarily in memory, significantly reducing forensic artifacts. The malware establishes persistent WebSocket-based command-and-control communication through HTTP protocol upgrades, allowing malicious traffic to blend with legitimate activity. Chinese-language artifacts were observed throughout the infrastructure and code, though attribution remains at moderate confidence. The campaign demonstrates characteristics of a mature, ...

Date

  • Created: June 4, 2026, 10:52 p.m.
  • Published: June 4, 2026, 10:52 p.m.
  • Modified: June 5, 2026, 6:41 a.m.

Indicators

  • be31a63cad112723178289968ad6f93a576c5a7984099c42eec3521cdf6e5fc0
  • 949acbe543fc244ffbc981ea169067da7c5792af3c3d19b2c31b3d7e19106880
  • 7d87a86dbd2379ef2516c99258137cd9c25ca19c48aeb096c5332c02fcbf16d0
  • 4c9061a07d667bf7dd6f597a43a8552af2f4277b7be06d6ea138abdb668d6a49
  • 185b7a487316454da04e9cc0fe6eb370bb2955cf6096fe3e8c02c46f8989ba37

Additional Informations

  • zhengfu666.com
  • naiqja.icu
  • appradarr.cc
  • taxations.cn-web-okooo.com
  • d.pc-weide.com
  • asdqxcdsa.icu
  • mnb-ny.com
  • guhxmg.com
  • zh-welcome-1xbet.com
  • ws4962.com
  • India
  • British Indian Ocean Territory
  • Japan