Executive Summary
Operation DragonReturn is a sophisticated cyber-espionage campaign attributed with moderate-to-high confidence to a China-nexus threat cluster, possibly Silver Fox. The campaign specifically targets the Indian taxpayer ecosystem, including corporate finance teams and government contractors, by impersonating the Income Tax Department of India during the AY2026-27 filing season. The attackers utilize highly convincing bilingual lure documents and a spoofed government infrastructure (govtop[.]one) to distribute malicious payloads.
The technical execution involves a complex multi-stage infection chain that leverages DLL side-loading, steganography (hiding payloads in background.jpg), and fileless .NET execution to deploy DcRAT. The operation is characterized by its high degree of operational maturity, evidenced by the rotation of payloads every 7-10 days to maintain a zero-detection rate on signature-based security tools. The primary objective is suspected to be long-term covert access for intelligence collection and sensitive data exfiltration from Indian financial and government sectors.
Key Details
Threat Name
Operation DragonReturn
Affects
—
Adversary
Silver Fox Other Adversaries and Aliases: SideCopy; APT-C-36; REF3864
MITRE Techniques
Malware/Tools
DcRAT, AsyncRAT, ValleyRAT, SADBRIDGE, GOSAR, Quasar RAT
