A suspected China-linked threat group is targeting Indian taxpayers, tax professionals, and corporate finance teams through a spear-phishing campaign called Operation DragonReturn, which impersonates India's Income Tax Department. Victims are tricked into downloading a fake tax filing utility that deploys DcRAT, a remote access trojan capable of stealing sensitive data, taking screenshots, and exfiltrating information to remote servers. Infrastructure analysis points to Chinese-linked IP addresses and overlaps with the known cybercrime group Silver Fox, suggesting the campaign is a deliberate, sustained effort aimed at intelligence collection and data theft.