A suspected China-nexus threat activity cluster, codenamed Operation DragonReturn by Seqrite Labs, has been targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver the DcRAT remote access trojan. The campaign, first observed on May 18, 2026, coincides with India’s annual income tax filing season.
The attack chain begins with spear-phishing emails impersonating the Income Tax Department of India, using tax violation and penalty lures to create urgency. Victims are tricked into clicking a malicious link (“govtop[.]one/incometax”) embedded in PDF attachments. The landing page prompts download of a ZIP archive containing a fake offline tax filing utility that sideloads a malicious DLL (“nvdaHelperRemote.dll”), which injects a payload into memory. The payload checks for administrative privileges, evades analysis environments, and retrieves a JPG image from a hard-coded server (“204.194.48[.]250”) to conceal a secondary DLL payload. Persistence is achieved via a Windows service named MixedSvc.
The final payloads include a .NET malware loader that disables Windows AMSI and decrypts DCRat, and a second payload for screenshot capture and data exfiltration to “kkxqbh[.]top.” Infrastructure analysis reveals IP addresses belonging to ChinaNet and a Chinese-language web management panel on the DCRat C2 server (“223.26.63[.]40”). Seqrite also identified overlaps with the Silver Fox Chinese cybercrime group, which previously used tax-themed phishing to deliver ValleyRAT.
Separately, LevelBlue and Cybereason reported campaigns using fake LINE installers and salary adjustment lures to distribute ValleyRAT, with techniques like PoolParty Variant 7, previously linked to the SADBRIDGE loader and GOSAR malware. Elastic Security Labs attributed similar intrusions to REF3864.
CVEs: CVE-2026-55200, CVE-2026-46817
Attack groups: Silver Fox, REF3864
Malware: DcRAT, ValleyRAT, SADBRIDGE, GOSAR, Quasar RAT
Companies: Seqrite Labs, LevelBlue, Cybereason, Elastic Security Labs
Original source: thehackernews.com