Operation DragonReturn — China-Nexus DcRAT Multi-Stage Espionage Campaign Targeting Govt. of India Ministry of Finance / Income Tax Infrastructure — Threadlinqs Intelligence
As of 2026-06-27, Operation DragonReturn — China-Nexus DcRAT Multi-Stage Espionage Campaign Targeting Govt. of India Ministry of Finance / Income Tax Infrastructure is a critical-severity malware threat attributed to DragonReturn (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 41 indicators of compromise.
Threat ID: TL-2026-0956 · Severity: CRITICAL · Status: ACTIVE · Category: MALWARE
Attribution: DragonReturn · China · ESPIONAGE
Operation DragonReturn is an active China-aligned cyber-espionage campaign (medium-to-high confidence, infrastructure and TTP overlaps with the Silver Fox cluster) that abuses India's AY2026-27 ITR
Operation DragonReturn is a sustained, targeted cyber-espionage campaign observed by Seqrite Labs between 18 May and 17 June 2026 against the Government of India's financial and tax ecosystem, including taxpayers, chartered accountants, tax consultants, corporate finance teams, and government contractors across India. The operators time the campaign to the AY2026-27 Income Tax Return (ITR) filing season and impersonate the Income Tax Department / Ministry of Finance.
Initial access is achieved via spear-phishing emails carrying a PDF attachment that cites real legal provisions (Income Tax Act Sections 271(1)(c) and 276C), a fabricated signatory ('Raj Kumar Sharma, Assistant Commissioner of Income Tax'), and reference number TAX/PEN/2026-142. The PDF embeds a link to govtop[.]one/incometax, which redirects to a ZIP named 'Common_Offline_Utility_ITR-1_to_4_AY2026-27.zip'. The ZIP delivers a downloader, COU_ITR-1_to_4_AY2026-27.exe, that impersonates the official ITR offline utility.
The execution chain is multi-stage. The Stage-1 downloader uses sc.exe (Windows Service Control) via cmd.exe to register a malicious auto-start service 'MixedSvc' with display name 'Windows Mixed Reality Service' and binary path C:\Program Files\Windows Media Player\Mixed Reality.exe. A companion DLL, nvdaHelperRemote.dll (exports injection_initialize() and injection_terminate()), performs a privilege check via CheckTokenMembership() and a UAC bypass via ShellExecuteW() with the 'runas' verb, creates the mutex Global\ShitSetupOn26126k, and spawns worker threads. The loader downloads a steganographic container lllyd.jpg (saved as C:\Windows\background.jpg) and extracts a 504 KB DLL payload written to C:\Program Files\Windows Media Player
vdaHelperRemote.dll. It then enumerates processes via CreateToolhelp32Snapshot(), injects into svchost.exe by allocating executable memory, writing the decrypted payload using dynamic API resolution, and creating a remote thread before terminating the original process. Multi-payload deployment uses WTSEnumerateSessionsW() to drop two payloads per active Terminal Services session, writing status to C:\debug.txt (format client=<id>) and using marker files to prevent re-deployment.
Payload A is a DcRAT-family .NET RAT loaded filelessly. Its native loader patches AmsiOpenSession() in memory using VirtualProtect() to disable AMSI scanning, performs anti-sandbox timing checks via GetTickCount64() loops, decrypts an embedded AES-encrypted resource via Windows CNG (BCryptOpenAlgorithmProvider/BCryptDecrypt) with a hardcoded 16-byte key, then initializes the CLR (CLRCreateInstance, .NET 4.0.30319), loads the managed assembly via AppDomain::Load_3() and invokes its entry point via MethodInfo::Invoke_3() entirely in memory. The RAT establishes a TLS channel via System.Net.Security.SslStream to 223.26.63.40:2671 / ikkkkddd[.]com, registers the victim via IdSender.SendInfo(), and exfiltrates an extensive fingerprint (HWID, username, OS version/architecture, executable path, malware version, privilege level, active window title, installed AV products, executable timestamp, campaign group identifier, operator notes, and system idle time). Field names are resolved at runtime via string deobfuscation, serialized as MessagePack and ZIP-compressed before transmission.
Payload B is a surveillance component providing screen capture via an embedded desktop-capture library (dsc_* exports), TurboJPEG compression (tjInitCompress/tjCompress2/tjFree/tjDestroy), and zlib compression (compress2/uncompress). It resolves its primary C2 kkxqbh[.]top in a DNS loop, with automatic connection recovery and periodic state monitoring on a dedicated thread.
Infrastructure is hosted on ChinaNet (AS4134, China Telecom Jiangxi), CTG Server Limited (AS152194), and Turing Group Limited (AS140869), geolocated to Nanchang, Jiangxi Province, China, with a Chinese-language management panel ('豪凌1.6 - Web管理面板'). Attribution is medium-to-high confidence to a Chin
Target sectors: government, financial, taxation, professional services, corporate finance
Target regions: India, Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 41 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, CRITICAL, threat intelligence, cybersecurity, T1566, T1566, T1204, T1059, T1106, T1569, T1543, T1547, T1548, T1027