Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF Tax Infrastructure via Multi-Stage DcRAT Deployment

0
Medium
Published: 06/26/2026 (06/26/2026, 12:50:31 UTC)
Source: AlienVault OTX General

Description

A sophisticated China-aligned cyber espionage campaign targeting India's tax infrastructure was identified between May and June 2026. The operation impersonates the Income Tax Department, Ministry of Finance, exploiting the AY2026-27 ITR filing season to target corporate entities, tax professionals, chartered accountants, and taxpayers. The attack employs spear-phishing emails with malicious attachments mimicking legitimate government utilities. The multi-stage infection chain deploys DcRAT through steganographic payload concealment, fileless .NET execution, AMSI bypass, and Windows service persistence. The threat actor demonstrates operational maturity through active payload rotation achieving 0/66 detection rates, encrypted TLS-based C2 communications, and infrastructure hosted across multiple ASNs linked to China. The campaign shows overlaps with the China-nexus threat actor Silver Fox, featuring screen capture capabilities, data exfiltration, and systematic intelligence collection from high-value India...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/31/2026, 12:45:11 UTC

Technical Analysis

Operation DragonReturn is a sophisticated cyber espionage campaign identified in mid-2026 targeting India's tax infrastructure, specifically the Ministry of Finance and Income Tax Department. The attackers use spear-phishing emails with malicious attachments mimicking legitimate government utilities to infect targets including corporate entities and tax professionals. The infection chain deploys DcRAT malware through advanced techniques such as steganographic payload concealment, fileless .NET execution, AMSI bypass, and Windows service persistence. The threat actor rotates payloads to maintain zero detection rates across multiple antivirus engines and uses encrypted TLS-based command and control communications hosted on infrastructure linked to China. The campaign overlaps with the China-nexus threat actor Silver Fox and includes capabilities for screen capture, data exfiltration, and systematic intelligence gathering from high-value targets in India.

Potential Impact

The campaign targets sensitive tax-related entities in India, potentially compromising confidential financial and personal data through espionage activities. The use of advanced evasion techniques and persistent malware deployment increases the risk of prolonged undetected access and data exfiltration. The operation could disrupt tax infrastructure operations and undermine trust in government communications during a critical tax filing period.

Defensive Guidance

No official patch or fix is available as this is a targeted malware campaign rather than a software vulnerability. Organizations should exercise heightened caution during the AY2026-27 tax filing season, especially regarding spear-phishing emails impersonating government entities. Recommended mitigations include user awareness training to recognize phishing attempts, blocking or sandboxing suspicious email attachments, and monitoring for indicators of compromise related to DcRAT. Since the campaign uses fileless execution and AMSI bypass, endpoint detection and response solutions with behavioral analysis capabilities may help detect anomalous activity. There is no vendor advisory indicating that no action is required or that the threat is already mitigated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.seqrite.com/blog/operation-dragonreturn-china-nexus-cyber-espionage-campaign-targeting-govt-of-india-mof-tax-infrastructure-via-multi-stage-dcrat-deployment/"]
Adversary
Void Arachne
Pulse Id
6a3e75975494e990e7421b4d
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip27.50.54.191
ip117.44.201.119
ip118.107.0.197
ip204.194.48.250
ip223.26.63.40

Hash

ValueDescriptionCopy
hash7ec462f138432f4da43d942488d3d428
hashb26c01dfcc0cdcb30f4a9058f880fb80
hashdda082a12bb43eb34b9b37bf9e62d5f0
hash5260ac8e82c1280950425bb12ddfb5435ff20539
hash7d06bac0114e4c1e9a300d6310a29cf92956c933
hashac2eeef05f568ad36bdcd807159313862a84387d
hash19ca5fe04ca45a18c5bad9658ff73a8f39fe20ced78f690595f1b4c5a90af324
hash2f2f8f92af86fb962c30c4c1c9d673f9d94886373d0fcf78f8d105c051ffc643
hash34d1231a3bf1e13a9b90daecb5c74d52aea94ca54427b203d77e1adc61a5c4f9
hash4a040770fd81d0db9e04cb8dbd2e07e61969072962bb4e736b7c7001444cc2fa
hash589aa1f7252cae74538343cd35443c0a8f58ed280f2016918b6e539a0c09529a
hash5a00485968679dc0ed6d80b659f48287603864c223e952918d2c2aaddfa2d280
hash5e97f7c17bf0466355be0438c7cc3e2e4d125e31368f2fbcb8e1d79cb97f137a
hash6c774188a54ae07ae896abdf1ea6695cc29f529388888665e05322af3e9178e1
hash7e142c8fa614cc39d0453aa648b12209821c6bcbb77ee02094f70161b40d50ae
hash8ed95259300ca268279867d2999d9c4f6585c6c45308635fc39af87da27546b5
hasha8614dfad5fd2a79302a7c4829a0fed6f3a0a46b11beb28f89531cdfa83d32b3
hashb0fcd7d9396e70b89e8292f6b80f933607b6fc9a9d3d4dd4ca69b408a2625932
hashc6651d6ce31c3a00357e579981d48c0da942b5bbe1582bf3d612a07dc3bc0ff6
hashc6fc06db6a1318152c09200352b40c8fa794f1089988835c1df92174347be8ec
hashec5d4103b3d97885e9575ad045b2ef5467bf9fccf71828e418e6488d78983146
hasheccff5c026a01cbe91db45cd0289f8822985aa5183f096d8add69762696d100d
hashfc17d5b4d64cb61a5aa8fb6bbe1e94885f129b2bf8ee91bca1ccca2b537f6616

Url

ValueDescriptionCopy
urlhttp://govtop.one/incometax

Domain

ValueDescriptionCopy
domain1kkkkddd.com
domaingovtop.one
domainikkkkddd.com
domainjiayingjing.com
domainkkxqbh.top
domainsimaqz.com

Threat ID: 6a3ebd81d9e07477746b8cb7

Added to database: 06/26/2026, 17:57:21 UTC

Last enriched: 07/31/2026, 12:45:11 UTC

Last updated: 08/08/2026, 12:17:55 UTC

Views: 161

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses