BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

China-linked hackers target Indian taxpayers via tax phishing

Operation DragonReturn targets Indian taxpayers with DCRat; China-linked ValleyRAT campaigns spread via phishing.

  • A suspected China-nexus cyber campaign named Operation DragonReturn is targeting Indian taxpayers and financial professionals with sophisticated phishing emails.
  • The attack uses fake tax department documents to deploy a multi-stage malware, including the DCRat remote access trojan, designed for data theft and long-term system access.
  • Infrastructure analysis and tactical overlaps link the campaign to ChinaNet and the known Chinese cybercrime group Silver Fox.
  • Separately, two other campaigns are distributing the ValleyRAT malware via fake software installers and phishing emails targeting Chinese- and Japanese-speaking users.

A suspected China-aligned cyber espionage campaign, first observed on May 18, 2026, is precisely targeting Indian taxpayers and corporate finance teams during the tax filing season. Dubbed Operation DragonReturn by Seqrite Labs, the operation uses spear-phishing emails impersonating India’s Income Tax Department to deliver a remote access trojan.

- Advertisement -

The sophisticated attack begins with a malicious link embedded in a PDF, leading to a bogus tax department landing page. Consequently, users are tricked into downloading a malicious ZIP archive that sideloads a payload, establishing persistence as a Windows service named MixedSvc. Researchers noted the campaign is “not opportunistic – the precision of the lure document, the use of real legal citations, bilingual content, and active payload rotation indicate a deliberate, resourced, and sustained threat operation focused exclusively on the Indian taxpayer ecosystem,” as detailed in their report.

The final payload includes a .NET loader that disables security scans and deploys DCRat, while a second module exfiltrates data to a remote server. However, the campaign’s infrastructure, including IPs from ChinaNet and a Chinese-language server panel, strongly suggests a China-nexus threat actor. Meanwhile, security firm LevelBlue said it detected separate campaigns spreading ValleyRAT using fake installers and phishing emails.

These parallel attacks employ techniques like PoolParty Variant 7 for injection, which has been previously linked to the SADBRIDGE loader described by Elastic Security Labs. Furthermore, Cybereason researcher Hajime Takai noted the commonalities suggest these campaigns may originate from the same threat actor group.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Trump says US weighs buying ‘sizable’ Bitcoin reserves

President Trump says the US is considering buying "sizable" amounts of Bitcoin and other...

Trump touts ‘fair’ Clarity Act at White House crypto meeting

President Donald Trump called on Congress to pass a "fair version" of the Clarity...

Rollbit co-founder doxxed accused of theft and rigged games

An online researcher has attempted to doxx the pseudonymous co-founder of crypto casino Rollbit,...

Crypto-backed PAC candidates win 4 of 5 primaries in key races

Four of five candidates backed by the crypto-aligned PAC Fairshake won primaries or advanced...

BRICS 2026: Modi pushes CBDC payment link at summit

The BRICS 2026 summit in New Delhi will spotlight a CBDC payment bridge to...

Must Read

How to Buy VPS with Crypto from Hostinger – Step by Step guide

Did you know that nowadays you can use Bitcoin to purchase a Windows VPS? If you’re here, you’re probably wondering how to do it....
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading