BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

China-linked hackers target Indian taxpayers via tax phishing

Operation DragonReturn targets Indian taxpayers with DCRat; China-linked ValleyRAT campaigns spread via phishing.

  • A suspected China-nexus cyber campaign named Operation DragonReturn is targeting Indian taxpayers and financial professionals with sophisticated phishing emails.
  • The attack uses fake tax department documents to deploy a multi-stage malware, including the DCRat remote access trojan, designed for data theft and long-term system access.
  • Infrastructure analysis and tactical overlaps link the campaign to ChinaNet and the known Chinese cybercrime group Silver Fox.
  • Separately, two other campaigns are distributing the ValleyRAT malware via fake software installers and phishing emails targeting Chinese- and Japanese-speaking users.

A suspected China-aligned cyber espionage campaign, first observed on May 18, 2026, is precisely targeting Indian taxpayers and corporate finance teams during the tax filing season. Dubbed Operation DragonReturn by Seqrite Labs, the operation uses spear-phishing emails impersonating India’s Income Tax Department to deliver a remote access trojan.

- Advertisement -

The sophisticated attack begins with a malicious link embedded in a PDF, leading to a bogus tax department landing page. Consequently, users are tricked into downloading a malicious ZIP archive that sideloads a payload, establishing persistence as a Windows service named MixedSvc. Researchers noted the campaign is “not opportunistic – the precision of the lure document, the use of real legal citations, bilingual content, and active payload rotation indicate a deliberate, resourced, and sustained threat operation focused exclusively on the Indian taxpayer ecosystem,” as detailed in their report.

The final payload includes a .NET loader that disables security scans and deploys DCRat, while a second module exfiltrates data to a remote server. However, the campaign’s infrastructure, including IPs from ChinaNet and a Chinese-language server panel, strongly suggests a China-nexus threat actor. Meanwhile, security firm LevelBlue said it detected separate campaigns spreading ValleyRAT using fake installers and phishing emails.

These parallel attacks employ techniques like PoolParty Variant 7 for injection, which has been previously linked to the SADBRIDGE loader described by Elastic Security Labs. Furthermore, Cybereason researcher Hajime Takai noted the commonalities suggest these campaigns may originate from the same threat actor group.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Strait of Hormuz Reopening Months Away, Experts Warn

Crypto traders anticipate a rally in Bitcoin and risk assets if oil prices decline...

Bitcoin OG Selling Eases as Dormant BTC Movement Hits 4-Year Low

Dormant Bitcoin movement dropped to its lowest level since Q3 2022 in the second...

BitMart exchange shuts down, BMX token crashes by nearly 70%

BitMart will shut down its cryptocurrency exchange, ending trading services on Aug. 26 and...

SourTrade Malware Built in Browser Using Bun Runtime

SourTrade malvertising campaign targets cryptocurrency investors by assembling malware inside the victim's browser using...

Critical Fastjson flaw lets attackers hijack Spring Boot apps

A critical remote code execution vulnerability (CVE-2026-16723, CVSS 9.0) affects Alibaba's Fastjson library versions...

Must Read

How To Buy a Handshake Domain: A Step-by-Step Guide

Handshake Domains | Benefits | Drawbacks | How To Buy | Supported BrowsersIn this step-by-step guide, I am going to show you how to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading