China-Linked Cyber Espionage Targets India's Tax Ecosystem

China-Linked Cyber Espionage Targets India's Tax Ecosystem

First seen 31 Aug 2026, 12:53 UTC Itvoice.InCrnasia 76.2

Article Content

Browse articles
ThreatCluster

Seqrite has reported a cyber-espionage campaign named Operation DragonReturn, targeting India's taxpayer ecosystem by impersonating the Income Tax Department during the income tax return (ITR) filing season. The campaign employs phishing emails that appear as official communications, luring victims to download malware disguised as legitimate tax-filing software. This operation affects corporate finance teams, tax professionals, and individual taxpayers across India. The malware establishes persistence by creating a Windows service disguised as the 'Windows Mixed Reality Service' and embeds malicious components within trusted directories. The campaign is suspected to be linked to a China-aligned threat cluster based on infrastructure artefacts and known tactics. The malware is designed for long-term access to sensitive financial and taxpayer information rather than immediate financial fraud. Seqrite advises vigilance in verifying tax-related notices through official channels.

Key Points: • Operation DragonReturn targets India's taxpayer ecosystem using phishing emails. • Malware is disguised as legitimate tax-filing software to compromise systems. • The campaign is suspected to be linked to a China-aligned threat cluster.

Timeline

2026-08-31
Seqrite discloses Operation DragonReturn
Seqrite reveals a cyber-espionage campaign targeting India's tax ecosystem, leveraging phishing tactics and malware disguised as tax software.
Crnasia
2026-08-31
Details of phishing methods revealed
The campaign uses fake Income Tax Department communications to lure victims into downloading malware during the ITR filing season.
Itvoice.In