logo

Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF Tax Infrastructure via Multi-Stage DcRAT Deployment

ID: 078af5e0-2bcf-5fad-b882-768f74e989c6

STIX ID: report--078af5e0-2bcf-5fad-b882-768f74e989c6

Feed Name: Seqrite Blog

Threat Score
90/100

Date Published: 2026-06-26

Date Updated: 2026-07-19

Author: Dixit Panchal

...
...

Operation DragonReturn is a targeted, APT-style spear-phishing campaign impersonating India's Income Tax Department to push a multi-stage RAT using steganographic payloads, service persistence (MixedSvc), fileless .NET execution with AMSI bypass, and encrypted C2; Seqrite links the infrastructure and TTPs to a China-aligned nexus and provides IOCs, infrastructure details, and MITRE ATT&CK mapping for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.