threat-intel
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
High
Summary
A China-nexus threat actor is conducting a targeted phishing campaign against Indian taxpayers and tax professionals, leveraging fake tax filing utilities to deploy a remote access trojan (DcRAT). The campaign, dubbed Operation DragonReturn by Seqrite Labs, uses spear-phishing emails mimicking the Income Tax Department of India to deliver a multi-stage attack chain designed for financial gain and data theft. The campaign exhibits tactical overlaps with the Chinese cybercrime group Silver Fox, known for tax-themed phishing campaigns delivering ValleyRAT.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
