Fake Indian tax portal used to plant spyware on finance teams' computers

A suspected Chinese hacking group is posing as India's Income Tax Department to slip a remote-control trojan onto the machines of accountants and corporate finance staff.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a dimly lit Indian accountant's desk at night, showing an open laptop with a generic tax form on screen
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Security firm Seqrite Labs has named the campaign Operation DragonReturn and linked it to a suspected China-based hacking group.
  • The attackers send fake emails pretending to come from India's Income Tax Department, aimed at taxpayers, tax advisers and finance teams inside Indian companies.
  • The final payload is DcRAT, a remote access trojan that lets attackers watch and control an infected machine from afar.
  • The attack moves through several hidden download stages before the spyware lands, making individual files look harmless to antivirus tools.
  • Victims risk theft of tax filings, client data and banking credentials.

Someone in India opens what looks like a routine email from the tax office. It talks about a filing utility, the sort of small program accountants download every year around deadline season. They click. Nothing obvious happens. In the background, their computer has just been handed to a stranger.

That's the shape of Operation DragonReturn, a campaign flagged by researchers at Seqrite Labs and reported by The Hacker News. They believe the attackers have a China nexus, though they've stopped short of naming a specific state-backed crew. It fits a pattern we've been tracking: our 29 June story on Mustang Panda documented a China-aligned group running parallel operations against Indian government targets that same month.

The targets are deliberate. Indian taxpayers, chartered accountants, and finance departments sitting on mountains of sensitive paperwork.

How does the attack actually work?

It starts with a spear-phishing email, a targeted fake message written to look like it comes from someone the victim trusts. Here the sender impersonates India's Income Tax Department, and the lure is a tax filing utility that Indian filers really do use.

Opening the attachment kicks off a multi-stage chain. Each stage pulls down the next piece quietly, so nothing looks alarming at any single step. The failure mode is familiar: individual files look boring, the combined result is a full spyware kit.

The final payload is DcRAT. RAT stands for remote access trojan, malicious software that gives an attacker a live back door into the machine. Once installed, it can log keystrokes, capture screenshots and pull passwords from browsers. For a finance team that means client tax returns, PAN numbers, and anything sitting in a shared drive.

Should ordinary taxpayers be worried?

Mostly this campaign targets professionals, not individual filers, but the same trick works on anyone. If you file taxes in India, treat any email claiming to be from the tax department with suspicion, especially around deadlines. The real Income Tax Department doesn't send filing utilities as email attachments. Downloads should come from the official portal you type into the browser yourself.

If you run a small accounting practice, the practical advice is duller and more useful. Don't open attachments from unexpected senders. Keep tax utilities on a machine that isn't also used for general email and browsing. Turn on multi-factor authentication, the extra one-time code step, on every account that touches client data.

Why does this one matter?

Campaigns like this succeed because the lure is boring and plausible. Nobody's excited to receive a tax notice. People click through them fast, half-reading, wanting the task off their plate. That's exactly the mental state attackers count on.

What the post-mortem will say, if any victim firm bothers writing one: the antivirus alert probably did fire at stage two or three. Someone dismissed it. They always do.

Assume any email offering a tax utility is hostile until proven otherwise, and get your finance team into the habit of downloading tools only from the URL they typed themselves.

© 2026 Threat Vectr