Operation DragonReturn: India MoF Tax Lure Payload Execution and C2 Contact
This rule identifies indicators of compromise associated with the DragonReturn malware and DcRAT, including malicious file names, suspicious process execution, DNS resolution of known malicious phishing domains, and network communication with documented C2 infrastructure.
Cortex XDR

