• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Operation DragonReturn: India MoF Tax Lure Payload Execution and C2 Contact

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated Jun 30, 2026•0•0•1

    This rule identifies indicators of compromise associated with the DragonReturn malware and DcRAT, including malicious file names, suspicious process execution, DNS resolution of known malicious phishing domains, and network communication with documented C2 infrastructure.

    Cortex XDR

    Tags

    T1566.001 - Spearphishing AttachmentT1204.002 - Malicious FileT1071.001 - Web ProtocolsTA0001 - Initial AccessTA0002 - ExecutionTA0011 - Command and ControlProcess CreationFile CreationNetwork Connection OutboundDNS QueryMalware DetectedWindowsGeneric Security Tool Log

    Found in

    • Operation DragonReturn: China-Nexus Cyber Espionage Against Indian TaxpayersLast updated Jul 6, 2026

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?