TA4922 Operation DragonReturn tax-themed phishing campaign
Campaign
Summary
Hide ▲
Show ▼
A TA4922 phishing campaign has used tax-themed lures and attacker-controlled landing pages to deliver malware to Indian taxpayers and related finance personnel. The operation, tracked as Operation DragonReturn, spans four identified campaigns between April and early June 2026 and shows a sustained delivery pattern.
Related Happenings
Operation DragonReturn tax-phishing campaign targeting Indian taxpayers
Campaign
H score31
First: 06.07.2026 13:58
Last: 06.07.2026 13:58
Sources 1
About this happening:
The Operation DragonReturn campaign is using spear-phishing and fake tax-filing lures to push remote access trojans into Indian taxpayer and finance environments, crea...
Operation DragonReturn tax-phishing campaign targeting Indian taxpayers
CampaignAbout this happening: The Operation DragonReturn campaign is using spear-phishing and fake tax-filing lures to push remote access trojans into Indian taxpayer and finance environments, crea...
Latest development: 08.07.2026 03:00
Updated reporting on July 8, 2026 added Cyderes findings that Operation DragonReturn also uses fake websites impersonating the Indian Income Tax Department to deliver ZIP archives disguised as the common offline utility. The same chain deploys two implants, including a Gh0st RAT derivative that connects to kkxqbh[.]top on port 6666 and an AsyncRAT-family RAT that connects to ouewop[.]com on port 6351, while separate C2 channels, session-wide injection, and multiple initial access vectors improve persistence and resilience.
TA4922 expanded European phishing-and-malware campaign
Campaign
H score40
First: 04.06.2026 00:45
Last: 04.06.2026 00:45
Sources 1
How related:
"It's worth mentioning here that this attack was documented in detail earlier this month by Seqrite Labs and Cyderes Howler Cell. Seqrite Labs is tracking the activity under the moniker Operation DragonReturn."
About this happening:
TA4922 is a China-linked cybercrime campaign that now also uses the Cruciferra crypter, while continuing its income tax-themed phishing activity against Indian t...
TA4922 expanded European phishing-and-malware campaign
CampaignHow related: "It's worth mentioning here that this attack was documented in detail earlier this month by Seqrite Labs and Cyderes Howler Cell. Seqrite Labs is tracking the activity under the moniker Operation DragonReturn."
About this happening: TA4922 is a China-linked cybercrime campaign that now also uses the Cruciferra crypter, while continuing its income tax-themed phishing activity against Indian t...
SideCopy Operation XENOFISCAL spear-phishing campaign targeting Afghan finance entities
Campaign
H score25
First: 02.06.2026 12:05
Last: 02.06.2026 12:05
Sources 1
About this happening:
The SideCopy-linked Operation XENOFISCAL spear-phishing campaign is targeting Afghanistan's Ministry of Finance and related provincial finance offices with Xeno RAT*...
SideCopy Operation XENOFISCAL spear-phishing campaign targeting Afghan finance entities
CampaignAbout this happening: The SideCopy-linked Operation XENOFISCAL spear-phishing campaign is targeting Afghanistan's Ministry of Finance and related provincial finance offices with Xeno RAT*...
Silver Fox tax-themed phishing campaign delivering ABCDoor and ValleyRAT
Campaign
H score36
First: 04.05.2026 14:57
Last: 04.05.2026 14:57
Sources 1
About this happening:
Silver Fox is running a tax-themed phishing campaign that now targets India with Income Tax Department lures and delivers ValleyRAT (aka Winos 4.0). The campai...
Silver Fox tax-themed phishing campaign delivering ABCDoor and ValleyRAT
CampaignAbout this happening: Silver Fox is running a tax-themed phishing campaign that now targets India with Income Tax Department lures and delivers ValleyRAT (aka Winos 4.0). The campai...
Tax-season credential phishing and RMM malware campaign
Campaign
H score42
First: 30.03.2026 18:00
Last: 30.03.2026 18:00
Sources 1
About this happening:
A tax-themed cyber campaign is using credential phishing, remote monitoring and management (RMM) tools, and fraud lures to target people handling financial data*...
Tax-season credential phishing and RMM malware campaign
CampaignAbout this happening: A tax-themed cyber campaign is using credential phishing, remote monitoring and management (RMM) tools, and fraud lures to target people handling financial data*...
Timeline
-
27.07.2026 13:51 2 articles · 2h ago
Cruciferra-linked tax phishing targets Indian taxpayers and finance teams
Initial DisclosureProofpoint identified a China-linked cybercrime group using the Cruciferra crypter in income tax-themed phishing against Indian taxpayers, tax professionals, and corporate finance teams. One campaign is attributed to TA4922 and tracked by Seqrite Labs as Operation DragonReturn, with attacker-controlled landing pages and ZIP files used to deliver malware. Proofpoint says four such campaigns were identified between April and early June 2026, and the same tooling has also been observed in other campaigns delivering XWorm, AdaptixC2, and zgRAT.
Show sources
- Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware — thehackernews.com — 27.07.2026 13:51
- Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware — thehackernews.com — 27.07.2026 13:51