Back Crnasia Suspected China-linked espionage campaign targets India's finance ecosystem: Seqrite
Seqrite, the enterprise security arm of Quick Heal Technologies, has disclosed a cyber-espionage campaign targeting India's taxpayer ecosystem, using fake Income Tax Department communications to compromise finance teams, tax professionals and businesses during the income tax return (ITR) filing season.
Dubbed Operation DragonReturn, the campaign impersonates the Income Tax Department of the Ministry of Finance and uses tax-season urgency to lure victims into downloading malware disguised as legitimate tax-filing software.
Based on infrastructure artefacts, Chinese-language web-management panels and overlaps with known tactics, techniques and procedures, researchers at Seqrite Labs suspect the campaign may be linked to a China-aligned threat cluster.
The campaign targets a broad cross-section of the financial and compliance ecosystem, including corporate finance and accounts teams, chartered accountants, tax consultants, filing agents, government contractors and individual taxpayers.
For MSSPs, cybersecurity partners and enterprise security teams, the findings highlight how trusted compliance workflows are becoming high-value attack surfaces, requiring stronger monitoring of finance systems, taxpayer data and government-facing communications.
The attack begins with phishing emails designed to appear as official Income Tax Department communications.
Recipients are directed to fraudulent websites built to closely resemble government portals. The fake notices use the Government of India emblem, bilingual Hindi-English formatting, fabricated reference numbers and references to genuine provisions of the Income Tax Act, including Sections 271(1)(c) and 276C, to create credibility and urgency.
Victims are then prompted to download a ZIP archive that mimics the Income Tax Department's offline filing utility used for preparing tax returns.
Researchers said the campaign exploits one of the most trusted and time-sensitive workflows in India's compliance ecosystem, turning a routine tax-filing process into a vehicle for malware delivery.
Once executed, the malware establishes persistence by creating a Windows service disguised as the "Windows Mixed Reality Service" and embeds malicious components within legitimate-looking directories and files.
Seqrite said the operation uses a multi-stage infection chain designed to conceal its final payload, reduce visibility and maintain long-term access to compromised systems.
The campaign ultimately deploys a remote access trojan (RAT) capable of collecting system information, identifying installed security products, gathering user information and determining administrative privileges.
Researchers also discovered desktop-capture and compression components, indicating the malware can capture screenshots and prepare collected information for exfiltration.
Seqrite believes the campaign is designed to establish sustained access to high-value financial and taxpayer information rather than execute opportunistic financial fraud.
While the company has not conclusively attributed the operation, it said multiple indicators point towards a suspected China-aligned threat actor.
According to Seqrite, the campaign's focus on India's tax infrastructure, combined with its persistence mechanisms and data-collection capabilities, indicates an effort to gain long-term visibility into sensitive financial and taxpayer data.
The findings suggest a broader challenge facing organisations during compliance and filing periods. Rather than relying on generic phishing tactics, attackers are exploiting trusted government brands, regulatory processes and filing deadlines to gain access to enterprise environments.
For businesses, the campaign reinforces the need to extend security monitoring beyond traditional IT users and infrastructure. Finance, accounts and taxation functions often handle highly sensitive corporate, employee and customer information, making them attractive targets for espionage-oriented campaigns.
Seqrite advised organisations to verify tax-related notices only through official Income Tax Department channels, avoid downloading software from unsolicited emails and treat communications claiming to originate from government agencies with caution.
The company also recommended monitoring for spoofed government domains, fraudulent tax-related websites and other indicators that frequently precede phishing campaigns of this nature.
The campaign highlights opportunity for MSSPs, MDR providers and cybersecurity partners to help customers secure compliance-driven workflows, strengthen finance-team awareness, and improve their ability to detect identity, email and endpoint compromises.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
