Operation DragonReturn: China-Nexus Cyber Espionage Against Indian Taxpayers
Score: 8/10

Operation DragonReturn: China-Nexus Cyber Espionage Against Indian Taxpayers

A China-nexus threat actor is targeting Indian taxpayers and government infrastructure using a multi-stage infection chain to deploy DcRAT via fake tax utility lures.

Executive Summary

Operation DragonReturn is a sophisticated cyber-espionage campaign attributed with moderate-to-high confidence to a China-nexus threat cluster, possibly Silver Fox. The campaign specifically targets the Indian taxpayer ecosystem, including corporate finance teams and government contractors, by impersonating the Income Tax Department of India during the AY2026-27 filing season. The attackers utilize highly convincing bilingual lure documents and a spoofed government infrastructure (govtop[.]one) to distribute malicious payloads.

The technical execution involves a complex multi-stage infection chain that leverages DLL side-loading, steganography (hiding payloads in background.jpg), and fileless .NET execution to deploy DcRAT. The operation is characterized by its high degree of operational maturity, evidenced by the rotation of payloads every 7-10 days to maintain a zero-detection rate on signature-based security tools. The primary objective is suspected to be long-term covert access for intelligence collection and sensitive data exfiltration from Indian financial and government sectors.

Key Details

Threat Name

Operation DragonReturn

Affects

—

Adversary

Silver Fox Other Adversaries and Aliases: SideCopy; APT-C-36; REF3864

Malware/Tools

DcRAT, AsyncRAT, ValleyRAT, SADBRIDGE, GOSAR, Quasar RAT

Report Score

8out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance6
Enterprise Relevance9
Clarity & Structure9
Technical Depth9

Sources