← BACK TO FEED
DcRATValleyRATspear-phishingSilver FoxChina-nexus threats

Chinese Hackers Dressed as India's Tax Authority Are Deploying DcRAT on Finance Teams

A suspected China-linked threat group is targeting Indian taxpayers, tax professionals, and corporate finance teams through a spear-phishing campaign called Operation DragonReturn, which impersonates India's Income Tax Department. Victims are tricked into downloading a fake tax filing utility that deploys DcRAT, a remote access trojan capable of stealing sensitive data, taking screenshots, and exfiltrating information to remote servers. Infrastructure analysis points to Chinese-linked IP addresses and overlaps with the known cybercrime group Silver Fox, suggesting the campaign is a deliberate, sustained effort aimed at intelligence collection and data theft.

A threat cluster with suspected ties to China has been running a targeted phishing operation against Indian taxpayers, tax professionals, and corporate finance staff, with the goal of dropping a remote access trojan capable of stealing sensitive data.

Seqrite Labs, which has been tracking the campaign under the name Operation DragonReturn, says it was first spotted on May 18, 2026. The timing is not accidental. It lines up neatly with India's annual income tax filing season, which is exactly the kind of cover a half-decent social engineering operation needs.

This is not spray-and-pray. The attackers put real effort into the lures. Phishing emails impersonate India's Income Tax Department, cite actual legal statutes, mix Hindi and English content, and rotate their payloads actively. Seqrite researchers Dixit Panchal and Soumen Burma describe it as a deliberate, resourced operation aimed squarely at the Indian taxpayer ecosystem. Read: someone planned this properly.

The attack starts with an email pushing a fake tax violation or penalty notice. There is a PDF attached. Inside the PDF, a link to a bogus domain (govtop[.]one/incometax) which serves up a landing page dressed to look like an official government resource. Victims are told to download a ZIP file containing what appears to be a standard offline tax filing utility. It is not.

Inside the ZIP is a malicious DLL, nvdaHelperRemote.dll, which sideloads itself and injects a further payload into memory. That payload checks whether it has admin privileges and, if not, fires off a UAC prompt to try and grab them. It also runs sandbox detection checks before doing anything interesting, a basic but effective precaution.

Once it is satisfied the environment is real, it pulls a JPG image from a hardcoded IP address (204.194.48[.]250) and saves it to C:\Windows\background.jpg. The image is not decorative. A 504KB DLL is hidden inside it using steganography, then extracted and dropped to the Windows Media Player directory. The malware then copies itself as Mixed Reality.exe and installs a Windows service called MixedSvc to ensure it survives a reboot.

From there, two payloads are deployed. The first is a .NET loader that disables Windows AMSI scanning, dodges analysis tools, sets up persistence, and finally decrypts and loads DCRat onto the machine. DCRat is a well-known commodity remote access trojan that gives operators broad control over infected hosts. The second payload takes screenshots and ships data off to a remote server at kkxqbh[.]top.

Attribution is murky, as it usually is, but the infrastructure tells a story. The C2 server at 223.26.63[.]40 exposed a Chinese-language web management panel. The IP addresses involved belong to ChinaNet. Seqrite also found tactical and infrastructure overlaps with Silver Fox, a Chinese cybercrime group previously linked to tax-themed phishing campaigns delivering ValleyRAT.

Putting it together, Seqrite assesses this as the work of a China-aligned actor pursuing intelligence collection, credential theft, and systematic data exfiltration.

Separately, LevelBlue has flagged two related campaigns distributing ValleyRAT to Chinese and Japanese-speaking users. One uses malicious emails with salary-themed lures linking to ZIP files that kick off a DLL sideloading chain. The other uses fake software installers for LINE and other popular applications, deploying ValleyRAT via a technique called PoolParty Variant 7, which injects shellcode directly into explorer.exe.

That specific injection technique has appeared before in connection with SADBRIDGE, a loader used to drop GOSAR, a Golang reimplementation of Quasar RAT. That intrusion set, attributed by Elastic Security Labs to REF3864, previously targeted Chinese-speaking users with trojanised Telegram and Opera installers. Cybereason researcher Hajime Takai flagged the overlap in February 2026, stopping short of a firm attribution but noting the similarities are hard to ignore.

The throughline across all of this: commodity RATs, careful seasonal timing, and infrastructure that keeps pointing back to China.

READ NEXT
BusySnake: The Python Stealer Quietly Targeting Governments and Power GridsThis Cybersecurity Index Tracks Real Breaches and Refuses to Invent a Grand TotalCapital One Releases AI Vulnerability Hunter to the Public