As cited
Copy frozen at (site build).
threat intel
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
A suspected China-linked threat group is targeting Indian taxpayers and tax professionals with spear-phishing emails impersonating India's Income Tax Department to deploy DcRAT, a remote access trojan capable of stealing sensitive data. The campaign, labeled Operation DragonReturn, uses a fake tax filing utility as the infection vector in a multi-stage attack chain.
Why it matters: Indian taxpayers, accountants, and finance teams should treat unsolicited tax-related emails as high-risk; security teams in India and organizations with Indian operations need to monitor for DcRAT and implement email controls to block tax impersonation attacks.
- Source published
- First seen by Cybersecurity Tracker