{"id":1617,"date":"2026-07-06T15:17:37","date_gmt":"2026-07-06T15:17:37","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1617"},"modified":"2026-07-06T15:17:37","modified_gmt":"2026-07-06T15:17:37","slug":"suspected-china-nexus-hackers-use-fake-indian-tax-filing-utility-to-deploy-dcrat","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1617","title":{"rendered":"Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh0L8iGbVZ6lxBg26K2nsc6uYpFED8ZcgCtrh4C34U4oixLPC0OKHOWWpiPBfaSwe-tpOTbCqZfRZQTMoropayZXEm0GXTtKpyBuBPRk9zF-0WPRprknYiaI2DXLDZnQb8t70R7-0Fjl5G-NNCQFF-Ex40vQZMbUJmJ2JLyXJUjYdAVvgjl3_oBF5wbHrHl\/s1700-e365\/income-tax.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver a remote access trojan designed to steal sensitive data from compromised hosts.<\/p>\n<p>The multi-stage campaign, codenamed Operation DragonReturn by Seqrite Labs, involves sending spear-phishing emails impersonating the Income Tax Department of India. It was first observed on May 18, 2026. The activity, per the cybersecurity company, coincides with the annual income tax filing season in the country.<\/p>\n<p>\u00abIt is not opportunistic \u2013 the precision of the lure document, the use of real legal citations, bilingual content, and active payload rotation indicate a deliberate, resourced, and sustained threat operation focused exclusively on the Indian taxpayer ecosystem,\u00bb security researchers Dixit Panchal and Soumen Burma <a href=\"https:\/\/www.seqrite.com\/blog\/operation-dragonreturn-china-nexus-cyber-espionage-campaign-targeting-govt-of-india-mof-tax-infrastructure-via-multi-stage-dcrat-deployment\/\">said<\/a>.<\/p>\n<p>The end goal of the campaign is assessed to be the deployment of malware for financial gain or sensitive data theft.<\/p>\n<p>The attack chains begin with phishing messages masquerading as India&#8217;s income tax department, using tax violations and penalty lures to induce a false sense of urgency and trick users into clicking on a malicious link (\u00abgovtop[.]one\/incometax\u00bb) embedded within PDF attachments.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The bogus landing page, for its part, instructs users to download a ZIP archive containing what appears to be a <a href=\"https:\/\/www.incometax.gov.in\/iec\/foportal\/downloads\">common offline utility<\/a> provided by the department to file tax returns, but, in reality, is engineered to sideload a malicious DLL (\u00abnvdaHelperRemote.dll\u00bb), which, in turn, injects another payload into memory.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>This payload ensures it&#8217;s running with administrative privileges, and if not, triggers a User Account Control (UAC) prompt to get the user to run it with elevated permissions. Once launched, it performs checks to avoid executing within analysis and sandboxed environments, and then retrieves a JPG image (\u00ablllyd.jpg\u00bb) from a hard-coded server (\u00ab204.194.48[.]250\u00bb) and stores it as \u00abC:\\Windows\\background.jpg.\u00bb<\/p>\n<p>\u00abThis image file is used as a container for a secondary payload, from which a 504 KB DLL is extracted and written to &#8216;C:\\Program Files\\Windows Media Player\\nvdaHelperRemote.dll,'\u00bb Seqrite Labs explained. \u00abAfter extracting the payload, the malware copies itself as &#8216;Mixed Reality.exe&#8217; and establishes persistence by creating a Windows service named MixedSvc, configured to start automatically on system boot.\u00bb<\/p>\n<p>\u00abThis behaviour confirms that the sample functions as a downloader and installer, using image-based payload concealment and Windows service persistence to maintain long-term access to the infected system.\u00bb<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhruPjuEUNx3oeLkjZnayl5tAwDMOkr6p3k66Y98oyxhc664vGJunx2qJ9DkE0SHsUD4g3zKeID3UBEb8YQQrw8irnMVqwCvUG1redfiwaVTs-Jm5Ndu7gzx-H5A7UIFxiOKWPm4Jd6S1s2UYnXWEG8O3PoCVJ_NSuPFG7RslQDXymmCtYE_twfRBrJOWpJ\/s1700-e365\/seq.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhruPjuEUNx3oeLkjZnayl5tAwDMOkr6p3k66Y98oyxhc664vGJunx2qJ9DkE0SHsUD4g3zKeID3UBEb8YQQrw8irnMVqwCvUG1redfiwaVTs-Jm5Ndu7gzx-H5A7UIFxiOKWPm4Jd6S1s2UYnXWEG8O3PoCVJ_NSuPFG7RslQDXymmCtYE_twfRBrJOWpJ\/s1700-e365\/seq.png\" alt=\"\" border=\"0\" data-original-height=\"1200\" data-original-width=\"1311\"\/><\/a><\/div>\n<p>The \u00abMixed Reality.exe\u00bb binary is responsible for deploying two different payloads, one of which is a .NET malware loader that carries out anti-analysis checks, establishes persistence, disables Windows AMSI scanning, and decrypts and loads DCRat on the infected machine. The second payload features capabilities to take screenshots and exfiltrate data to a remote server (\u00abkkxqbh[.]top\u00bb).<\/p>\n<p>Exactly who is behind the activity is unclear, but infrastructure analysis indicates the use of IP addresses belonging to ChinaNet, as well as a Chinese-language web management panel exposed by the DCRat command-and-control (C2) server (\u00ab223.26.63[.]40\u00bb). In addition, Seqrite said it identified infrastructure and tactical overlaps with Silver Fox, a Chinese cybercrime group previously attributed to tax-themed phishing campaigns that deliver ValleyRAT.<\/p>\n<p>Based on these similarities, it&#8217;s suspected that the campaign is the work of a China-aligned threat actor conducted with an aim to establish covert access for intelligence collection, credential theft, and systematic data exfiltration, Seqrite concluded.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-1\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiqmM4NpfZsx4cw-HrXQlCjZQmrF8bYnmB23AmpOPi16kPNB9lvICjpdYEclxJwyQ9OE8GgzQ8aOEI68tRuxNqov0MHz2Sq8xEPiYWM3Js6FM5t2nm2JHWodmR7qVSot14ZtWVqQRQ6B88OnMaVxCPwRG7xGPoIIZxF6QAhWVhMkQfs11NjyNtHsGEUH4_q\/s728-e100\/sygnia-d-1.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The disclosure comes as LevelBlue <a href=\"https:\/\/www.levelblue.com\/blogs\/spiderlabs-blog\/an-analysis-of-valleyrat-infection-campaigns-from-fake-installers-japanese-malicious-emails\">said<\/a> it detected two distinct campaigns that employ fake installers for LINE and phishing emails with salary adjustment lures to distribute ValleyRAT targeting Chinese- and Japanese-speaking users.<\/p>\n<p>The email-driven campaign begins with a malicious email containing a URL link that, when accessed by the recipient, triggers the download of a ZIP archive. The archive acts as a foundation for a DLL side-loading chain, with the DLL ultimately downloading and executing ValleyRAT, a remote access trojan that allows operators to seize control of an infected system.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPAO6siEchsHCFfKF3KGOoGfR6CtsKX1ivdfrJgBb8_qBPnG8fbp5cvA1BQKaXHGunqIHe2vZWYaUYPNuJAy2LAimNyeVYwJ2AOY0W3FPF1B0p2eDFdIYnfl3FpXx7EI8noiyJUNY8HmXP8WUBGl3R49nPN3o5r_uEuJcXk6cHDY59pytsD-Y0Bd3JRCwB\/s1700-e365\/ValleyRAT-email.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPAO6siEchsHCFfKF3KGOoGfR6CtsKX1ivdfrJgBb8_qBPnG8fbp5cvA1BQKaXHGunqIHe2vZWYaUYPNuJAy2LAimNyeVYwJ2AOY0W3FPF1B0p2eDFdIYnfl3FpXx7EI8noiyJUNY8HmXP8WUBGl3R49nPN3o5r_uEuJcXk6cHDY59pytsD-Y0Bd3JRCwB\/s1700-e365\/ValleyRAT-email.png\" alt=\"\" border=\"0\" data-original-height=\"420\" data-original-width=\"755\"\/><\/a><\/div>\n<p>The fake installer attack chain, in contrast, employs bogus installers for popular software to deliver the malware using techniques like PoolParty Variant 7, while simultaneously focusing on anti-analysis and detection evasion, per Cybereason.<\/p>\n<p>Interestingly, the use of PoolParty Variant 7 to inject shellcode into \u00abexplorer.exe\u00bb has been previously observed in connection with a custom malware loader dubbed <a href=\"https:\/\/www.elastic.co\/security-labs\/under-the-sadbridge-with-gosar\">SADBRIDGE<\/a>, which is designed to deploy a Golang-based reimplementation of Quasar RAT known as GOSAR. The intrusion set, which targeted Chinese-speaking regions with malicious installers for Telegram and Opera, was attributed by Elastic Security Labs to REF3864.<\/p>\n<p>\u00abWhile we don&#8217;t have conclusive proof, these commonalities suggest they may have been created by the same threat actor,\u00bb Cybereason researcher Hajime Takai <a href=\"https:\/\/www.cybereason.com\/blog\/fake-installer-valleyrat\">noted<\/a> back in February 2026.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver a remote access trojan designed to steal sensitive data from&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1618,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[2369,2372,229,150,2370,338,2237,2368,860,2371],"class_list":["post-1617","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-chinanexus","tag-dcrat","tag-deploy","tag-fake","tag-filing","tag-hackers","tag-indian","tag-suspected","tag-tax","tag-utility"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1617","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1617"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1617\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1618"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1617"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1617"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1617"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}