Cybersecurity firm Seqrite says it has uncovered a sophisticated espionage campaign impersonating India’s Income Tax Department and targeting businesses during ITR filing season, putting the country’s financial backbone at risk.
A fake tax notice as bait
The operation, dubbed “DragonReturn” by Seqrite Labs, begins with a phishing email that looks like an official notice from the Ministry of Finance. It carries the Government of India emblem, bilingual Hindi-English text, fake reference numbers and even citations of real sections of the Income Tax Act to appear legitimate. The goal is to pressure recipients into acting fast.
From fake utility to full access
Victims are pushed toward a ZIP file disguised as the government’s own offline return-filing tool. Once opened, the malware quietly installs itself as a fake “Windows Mixed Reality Service,” burying its components inside trusted system folders to avoid detection. From there, it deploys a remote access trojan that can harvest system data, security software details, and user information, sending it back to attackers over encrypted channels. A second tool can capture and compress screenshots, underscoring the campaign’s intent to steal sensitive data.
Who’s behind it
Seqrite researchers say infrastructure clues, Chinese-language admin panels and overlaps with known attack patterns point to a China-aligned threat group. The targeting of India’s tax ecosystem, combined with the campaign’s stealth and persistence, reinforces the assessment that the attackers are seeking long-term access to financial and taxpayer records rather than a quick payday.
Who’s at risk
The campaign is aimed at corporate finance and accounts teams, chartered accountants, tax filing agents, government contractors and individual taxpayers—essentially anyone likely to be dealing with tax paperwork right now.
What Seqrite recommends
The company is urging people to verify any tax notice directly through official Income Tax Department channels, avoid clicking links or downloading files from unsolicited emails, and treat any “government utility” download with suspicion. For enterprises, Seqrite points to its own threat-monitoring and data-privacy tools as added layers of defence during high-risk filing periods.
