BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

China-linked hackers target Indian taxpayers via tax phishing

Operation DragonReturn targets Indian taxpayers with DCRat; China-linked ValleyRAT campaigns spread via phishing.

  • A suspected China-nexus cyber campaign named Operation DragonReturn is targeting Indian taxpayers and financial professionals with sophisticated phishing emails.
  • The attack uses fake tax department documents to deploy a multi-stage malware, including the DCRat remote access trojan, designed for data theft and long-term system access.
  • Infrastructure analysis and tactical overlaps link the campaign to ChinaNet and the known Chinese cybercrime group Silver Fox.
  • Separately, two other campaigns are distributing the ValleyRAT malware via fake software installers and phishing emails targeting Chinese- and Japanese-speaking users.

A suspected China-aligned cyber espionage campaign, first observed on May 18, 2026, is precisely targeting Indian taxpayers and corporate finance teams during the tax filing season. Dubbed Operation DragonReturn by Seqrite Labs, the operation uses spear-phishing emails impersonating India’s Income Tax Department to deliver a remote access trojan.

- Advertisement -

The sophisticated attack begins with a malicious link embedded in a PDF, leading to a bogus tax department landing page. Consequently, users are tricked into downloading a malicious ZIP archive that sideloads a payload, establishing persistence as a Windows service named MixedSvc. Researchers noted the campaign is “not opportunistic – the precision of the lure document, the use of real legal citations, bilingual content, and active payload rotation indicate a deliberate, resourced, and sustained threat operation focused exclusively on the Indian taxpayer ecosystem,” as detailed in their report.

The final payload includes a .NET loader that disables security scans and deploys DCRat, while a second module exfiltrates data to a remote server. However, the campaign’s infrastructure, including IPs from ChinaNet and a Chinese-language server panel, strongly suggests a China-nexus threat actor. Meanwhile, security firm LevelBlue said it detected separate campaigns spreading ValleyRAT using fake installers and phishing emails.

These parallel attacks employ techniques like PoolParty Variant 7 for injection, which has been previously linked to the SADBRIDGE loader described by Elastic Security Labs. Furthermore, Cybereason researcher Hajime Takai noted the commonalities suggest these campaigns may originate from the same threat actor group.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

AMD stock jumps on expanded Microsoft Azure partnership

AMD stock surged 1.58% on July 20, gaining an additional 3.56% in pre-market trading...

Moreno: DOJ, not states, to enforce CLARITY Act ethics

The White House reportedly agreed to ethics language for the CLARITY Act, potentially clearing...

Bitcoin ETFs Hit Five-Day Inflow Streak, BTC Above $65K

US spot Bitcoin ETFs recorded $226.9 million in net inflows on Monday, their fifth...

ServiceNow AI flaw exploited in wild, patch now

Threat actors are actively exploiting CVE-2026-6875, a critical sandbox escape vulnerability in the ServiceNow...

Cardano ADA Surges 4.2% as Market Rebounds

Cardano (ADA) has rallied by 4.2% in the last 24 hours and 9.3% in...

Must Read

Ethereum Hosting: TOP 10 Companies to Buy Hosting With Ethereum

If you are looking for Ethereum Hosting, you've hit the jackpot. In this article, we will present the 10 Best companies to buy hosting...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading