China-Linked Operation DragonReturn Hits Taxp
Cyber attack tests India's new data protection rules
Model Diplomat8 min readAsia

Operation DragonReturn: China-Linked Hack Tests India's Cyber Rules
China-linked "DragonReturn" hackers hit Indian taxpayers during ITR season, stress-testing New Delhi's DPDP breach rules and the Modi-Xi thaw.
Seqrite Labs, the research arm of Indian antivirus firm Quick Heal, disclosed on July 3, 2026 that a China-nexus threat cluster has run a live spear-phishing campaign — codenamed Operation DragonReturn — against Indian taxpayers, chartered accountants and corporate finance teams since May 2026, deploying the DcRAT remote-access trojan through fake Income Tax Department "offline utilities." The operation is more than a seasonal scam. It is the first significant China-attributed intrusion into India's financial-data plumbing since Prime Minister Narendra Modi met Xi Jinping at Tianjin in September 2025 — and it lands squarely inside the compliance window of the freshly notified Digital Personal Data Protection (DPDP) Rules 2025. That makes DragonReturn a live-fire test of two things at once: whether India's new breach-reporting regime works, and whether the diplomatic "thaw" with Beijing has any purchase on cyber behaviour.
What Seqrite actually found
The infection chain reads like a professional government-impersonation kit. Victims receive a bilingual English–Hindi email purporting to come from the Central Board of Direct Taxes, complete with real legal citations to sections of the Income-tax Act. A PDF lure warns of "corporate tax violations" and links to a spoofed government page that pushes a ZIP archive advertised as an "Income Tax Offline Utility." The archive drops a legitimate signed binary that sideloads a malicious DLL, which in turn creates a persistent Windows service named MixedSvc, disables endpoint scanners, decrypts a .NET assembly into memory, and finally launches DcRAT for keystroke capture, screenshot exfiltration and file theft, according to the technical write-up published by Security Online and corroborated by
The Cyber Security News.
Attribution is "medium-to-high confidence" China-nexus. Seqrite traced command-and-control servers to ChinaNet (AS4134), found Chinese-language strings in the DcRAT web panel, and flagged tradecraft overlap with Silver Fox — the Mandarin-speaking cluster that pioneered tax-themed phishing with ValleyRAT against mainland Chinese enterprises before pivoting to South and Southeast Asian targets, as tracked by threat.wiki. The clearest tell is temporal: the campaign spun up in May 2026, precisely as India's Assessment Year 2026–27 filing window opened.
Why this campaign matters more than the malware
DcRAT is commodity code. What is not commodity is the target set. The NITI Aayog tax-policy working paper released in October 2025 argues that direct-tax compliance is now the primary digital interface between the Indian state and its economically active population, with an expanding compliance base that includes both domestic taxpayers and foreign entities caught by the Significant Economic Presence rules. A campaign that harvests PAN numbers, Form 26AS extracts, banking credentials and corporate finance filings from that base is not petty fraud — it is bulk collection against a national fiscal database.
That reading tracks a documented pivot in Chinese operations. The Atlantic Council's March 2026 issue brief on China's cyber capabilities documents the "crossover between state and criminal" tooling — APT41's ColdLock ransomware, ChamelGang's CatB against India's All India Institute of Medical Sciences in 2022 — that lets Beijing use commodity malware to preserve plausible deniability while extracting strategic data. DragonReturn fits the template precisely: a cheap remote-access trojan, state-caliber targeting, deniable operators.
CrowdStrike's testimony to the U.S. House Homeland Security Committee in January 2025 quantified the pivot: China-nexus intrusions rose 150% across all sectors in 2024, with financial services up between 200% and 300%. India sits inside that curve. The country's own ministry of electronics
confirmed to Parliament that CERT-In tracked 20.4 lakh cyber-security incidents in 2024 — a 47% jump on 2022 — even as it declined, per longstanding policy, to publicly attribute any share to Chinese actors.
The attribution problem India refuses to solve
That silence is the story's second angle. The Observer Research Foundation, in an analysis of India's public-attribution posture, notes that New Delhi has come close to naming Beijing only once — in a 2018 CERT-In brief that claimed 35% of attacks on official Indian websites originated in China — and has since preferred to let private firms carry the accusation. Seqrite's DragonReturn write-up is the latest instance of that outsourced attribution: an Indian commercial lab does the naming, the government stays silent.
The Lee Kuan Yew School of Public Policy's post-Galwan analysis argues this reticence has costs: without an official baseline, each new intrusion is treated as an isolated incident rather than a data point in a decade-long campaign that has hit power grids in Ladakh, the Serum Institute of India, AIIMS Delhi, and now the taxpayer base. The Manohar Parrikar Institute's
2024–25 annual cyber report similarly catalogues a widening China-linked target set that now spans telecom (BSNL's 2024 breach), banking (a mid-2024 server compromise routed ₹16.5 crore through mule accounts) and cooperative-sector ransomware — but Indian officialdom continues to treat attribution as diplomatically inconvenient.
Carnegie's mapping of India's cybersecurity administration in 2025 points to why: the September 2024 Allocation of Business amendment made the National Security Council Secretariat the coordinating nodal agency, but split operational responsibility across MeitY, the Ministry of Home Affairs and the Department of Telecommunications. No single actor owns public attribution — and none has an incentive to make one during a diplomatic thaw.
The Tianjin thaw meets the ChinaNet C2
Here is the geopolitical bind. Modi's visit to Tianjin in September 2025 for the SCO summit was the first Indian prime-ministerial trip to China in seven years, and ISEAS's January 2026 analysis reads the meeting as a deliberate "floor" under a relationship that had been in freefall since Galwan. Direct India–China flights resumed on October 27, 2025 after a five-year hiatus. Al Jazeera's
reporting on the August 2025 Wang Yi visit laid out the accelerant: Donald Trump's 50% "reciprocal" tariff on Indian exports pushed New Delhi to hedge back toward Beijing, and the BBC's
subsequent reporting confirmed that visa curbs, trade routes at Nathu La and Lipulekh, and river-data sharing are all back on the table.
Carnegie's July 2026 paper on India's path forward with China argues the re-engagement is tactical, not strategic — a way to buy space against Trump-era unpredictability without conceding ground on the border. DragonReturn tests that thesis empirically. If the Ministry of External Affairs publicly attributes the campaign to a China-nexus actor, it risks the fragile Tianjin choreography. If it does not, it validates the ORF's warning that
China's cyber-espionage threat against India has broadened from critical infrastructure to commercial and civilian data with no cost imposed. The signal being sent to Beijing's operators is that filing-season intrusions carry no diplomatic downside.
DPDP Rules meet their first stress test
The domestic angle is arguably sharper. MeitY notified the DPDP Rules 2025 in November 2025. Rule 7, per the Takshashila Institution's briefing, requires data fiduciaries to intimate the Data Protection Board of any personal-data breach — including through phased rollout of security-safeguard obligations under Rule 6. The government's own
draft notification frames breach intimation as a core operationalising mechanism of the Digital Personal Data Protection Act, 2023.
Then, on 22 January 2026, MeitY convened Meta, Google, YouTube and Apple to propose compressing DPDP compliance timelines from 18 months to as little as immediate, per Takshashila's follow-up. Tax-preparation platforms, chartered-accountant SaaS providers and corporate ERP vendors — precisely the ecosystem DragonReturn is compromising — are now inside that window. Any firm whose CA-facing portal has been infected by a MixedSvc-persisted DcRAT beacon owes the Data Protection Board a breach notice. The DragonReturn campaign is, in effect, the first mass-scale trigger event for India's new privacy law.
CERT-In and CSIRT-Fin's Digital Threat Report 2024 — the first sectoral threat report co-authored by the Indian state — already flagged that the BFSI ecosystem's interconnected architecture means "a single cyberattack can have systemic repercussions." DragonReturn's targeting of finance-team endpoints is engineered to exploit exactly that interconnection: one compromised CFO desktop can seed access into payroll, banking APIs and vendor-master records.
Who wins, who loses
The winners. Beijing gets bulk collection against a South Asian G20 economy at a moment when it publicly courts New Delhi — the ideal cost profile. Silver Fox and adjacent contractors, characterised in the Atlantic Council's Sleight of Hand report as part of a decentralised hack-for-hire market, get another commercial reference. And Indian cybersecurity vendors — Seqrite, K7, and their listed parents — get validation for a domestic-champion narrative aligned with the ORF's tracking of
India's 2025 AI-driven cybersecurity shift, which recorded 265.52 million detections across 8 million endpoints in a single year.
The losers. Individual taxpayers whose PAN, Aadhaar-linked bank data and Form 16 information transit compromised endpoints. Chartered accountants and mid-market corporates who now face DPDP notification obligations without mature incident-response playbooks. And, quietly, India's declaratory China policy, which — per Carnegie's 2025 assessment of India's cyber statecraft — has "increasingly focused on the threat posed by its largest and most powerful neighbor" without translating that framing into operational deterrence.
Diplomat View
The forecast: DragonReturn will not be attributed publicly by the Government of India. Expect a CERT-In advisory naming indicators of compromise and calling out "state-aligned" actors without naming Beijing, and expect MeitY to lean on the campaign to justify accelerating Rule 6 and Rule 7 timelines against SME data fiduciaries. That is a policy win MeitY has wanted since January 2026; DragonReturn is the pretext, per ORF's reading of China's digital espionage playbook.
The forecast is falsifiable. It would be revised if (a) the MEA formally names a China-nexus cluster in a briefing before the Special Representatives' next border round; (b) CERT-In publishes an attribution dossier with technical indicators, breaking with post-2018 practice; or (c) the campaign expands to Government of India domain infrastructure, forcing a National Security Council response. The second-order risk to watch is Scam Inc-style commoditisation: the Economist's April 2026 investigation documented how Chinese-language malware-as-a-service is now sold to Southeast Asian criminal syndicates. DragonReturn's toolkit could be resold to those groups within the year.
What to watch next:
- July 31, 2026 — Indian ITR filing deadline for non-audit cases. Campaign volume will peak here.
- August 2026 — Next Special Representatives meeting on the India-China border, per the Tianjin roadmap. Any Indian government mention of DragonReturn signals a harder line.
- Q4 2026 — MeitY's decision on the compressed DPDP compliance timeline. A DragonReturn-triggered breach notice from a listed data fiduciary would be the first real-world test of Rule 7.
The Bottom Line
Operation DragonReturn is not a phishing story — it is the first documented China-linked intrusion into India's tax-compliance base since the Modi-Xi thaw, and it exposes the gap between New Delhi's rhetorical hardening on Beijing and its refusal to publicly attribute cyber operations. The campaign will most likely be absorbed as a domestic regulatory event under the DPDP Rules rather than a diplomatic one — which is exactly the outcome Beijing's operators are engineered to produce.
Discover more

US Politics
SNAP Food Assistance Faces Legal Challenges
In 2026, SNAP faces stricter eligibility rules and mounting legal challenges, threatening food assistance for the millions of Americans who rely on the program.

India
Congress Accuses Modi of Stalling Women's Law
Congress accuses Modi of stalling women's reservation law by linking it to delimitation, revealing a deeper electoral strategy.
US Politics
Congress Targets AI Chatbot Access for Terror
The House passed the Generative AI Terrorism Risk Assessment Act, focusing on AI's role in terrorism and potential surveillance implications.

Economics
US Tariffs on Brazil: A Political Play
US imposes 25% tariff on Brazil but exempts 66% of exports, targeting manufactured goods ahead of Brazil's October election. Analysis of the political calculus, exemptions, and Brazil's response options.