tldr
Securonix Threat Research tracks TAX#TRIDENT, an active fake Indian Income Tax-themed campaign that uses three delivery paths to reach Windows endpoints. The campaign starts with fake tax assessment lures and then moves victims toward ZIP files, VBScript downloaders, or PHP-looking web endpoints that actually return script content.
Two branches lead to the same signed ClientSetup payload. After execution, that payload installs a hidden client directory, creates service and driver persistence, writes runtime configuration, and starts outbound client traffic. A separate branch uses VBScript stages, cloud-hosted payloads, UAC policy changes, and a silent ManageEngine UEMS agent install.
The main story is not just the fake tax lure. The interesting part is how the same lure theme supports multiple execution paths: a simple ZIP-to-installer flow, a decoy-driven VBS-to-installer flow, and a PHP-named VBS flow that ends in endpoint-management enrollment.
Securonix Threat Research: Analyzes TAX#TRIDENT, a fake Indian tax campaign using ZIP files, VBScript, and signed management tools to gain durable endpoint access.
www.securonix.com