← All stories
● Covered by 1 source · 1 reportHigh impact

Chinese Hackers Target India’s Taxpayers with DcRAT via Phishing Scheme

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Chinese hackers use phishing to target Indian taxpayers.
  • Malicious PDF attachments lure victims into downloading malware.
  • Campaign coincides with India’s income tax filing season.

Overview of the Attack Campaign

Operation DragonReturn has been identified by Seqrite Labs as a sophisticated threat targeting Indian taxpayers and corporate finance teams. Initiated on May 18, 2026, the campaign uses spear-phishing emails that impersonate the Income Tax Department, linking directly to the annual income tax filing period in India.

Phishing Techniques Used

Attackers send phishing emails, creating urgency through messages about tax violations and penalties. These email links direct users to a fraudulent landing page, where they are prompted to download a ZIP file posing as a legitimate offline utility for tax filing.

Malware Deployment Process

Upon execution, the fake utility side-loads a malicious DLL ('nvdaHelperRemote.dll') that injects additional payloads into memory and seeks to run with administrative privileges. If it detects insufficient permissions, it triggers a User Account Control (UAC) prompt for elevation.

Persistence Mechanisms

The malware extracts an image from a remote server, which acts as a container for a secondary payload. This payload installs itself as 'Mixed Reality.exe' and creates a Windows service, 'MixedSvc,' enabling it to maintain persistence on the victim's system across reboots.

Significance of the Threat

The precision of the phishing strategy, including legal citations and bilingual content, underscores the resources behind this operation. The campaign's exclusive focus on India's taxpayer system reveals a targeted approach to financial gain through sensitive data theft.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A suspected group of Chinese hackers has launched Operation DragonReturn, targeting Indian taxpayers with sophisticated phishing emails disguised as communications from the Income Tax Department. The campaign utilizes fake tax filing utilities to deploy a remote access trojan (DcRAT), aimed at stealing sensitive financial data.