Back Itvoice.In Seqrite Uncovers China-Linked Cyber Espionage Campaign Targeting India's Tax Ecosystem
Seqrite, the enterprise security arm of Quick Heal Technologies Limited, a global provider of cybersecurity solutions, today disclosed Operation DragonReturn, a sophisticated cyber-espionage campaign targeting India’s taxpayer ecosystem by impersonating the Income Tax Department of the Ministry of Finance. The campaign uses tax-season urgency and counterfeit government communication to target corporate finance and accounts teams, tax professionals, chartered accountants, filing agents, government contractors and individual taxpayers across India.
Researchers at Seqrite Labs, India’s largest malware analysis facility, observed that the attack begins with a phishing email impersonating the Income Tax Department and directing recipients to a fraudulent webpage built to resemble an official government notice. The lure carries the Government of India emblem, bilingual Hindi-English formatting, fabricated reference details, a spoofed official email address and references to genuine provisions of the Income Tax Act, including Sections 271(1)(c) and 276C, to create credibility and urgency.
Victims are prompted to download a ZIP archive, closely mimicking the legitimate Income Tax Department offline filing utility used to prepare income-tax returns. Once executed, the malware establishes persistence through a Windows service disguised as the “Windows Mixed Reality Service,” and embeds malicious components in trusted-looking directories and files. The operation relies on a multi-stage chain designed to conceal its final payload that operates with reduce visibility and maintains access to infected systems.
The campaign then deploys a remote access trojan with encrypted command-and-control communications and capabilities that enable the collection of system information, user and security-product details, administrative status and other victim profiling data. A secondary component contains desktop-capture and compression libraries, indicating the ability to capture screenshots and prepare collected information for exfiltration.
Based on infrastructure artefacts, Chinese-language web-management panels, and overlaps with tactics, techniques and procedures associated with known activity, researchers at Seqrite Labs suspect that Operation DragonReturn is linked to a China-aligned threat cluster. The campaign’s focus on India’s tax infrastructure, combined with its covert persistence and data-collection capabilities, indicates a sustained operation aimed at establishing long-term access to high-value financial and taxpayer information.
The findings reinforce the broader risk facing organisations during high-volume compliance and filing periods: attackers exploit trusted government brands, legitimate-looking utilities and time-sensitive noticess to turn routine administrative workflows into entry points for espionage and data theft. Seqrite advises taxpayers and businesses to verify tax-related notices only through official Income Tax Department channels, avoid opening links or files sent through unsolicited emails, and treat software downloads that claim to be government utilities with caution.
For enterprises, Seqrite DRPS can add an important layer of protection by monitoring for fraudulent domains, spoofed government-facing lures, malicious infrastructure and other external threat signals that often precede a phishing campaign. Seqrite Data Privacy is equally important for enterprises managing taxpayer, employee, vendor and financial data, helping them discover, classify and protect sensitive information across complex environments in the event of a suspected compromise.
Quick Heal AntiFraud.AI can further support individuals and small businesses by helping identify suspicious links, fraudulent communications and scam patterns before they lead to credential loss or financial fraud. Together, these measures can help users recognize that a tax notice may not be what it appears to be, and pause before a deceptive message becomes a serious breach.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
