Find notable cyber news and cases, enriched with sources, timelines, and signals.

TA4922 Operation DragonReturn tax-themed phishing campaign

Campaign
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

A TA4922 phishing campaign has used tax-themed lures and attacker-controlled landing pages to deliver malware to Indian taxpayers and related finance personnel. The operation, tracked as Operation DragonReturn, spans four identified campaigns between April and early June 2026 and shows a sustained delivery pattern.

Related Happenings

Operation DragonReturn tax-phishing campaign targeting Indian taxpayers

Campaign
H score31 First: 06.07.2026 13:58 Last: 06.07.2026 13:58 Sources 1

About this happening: The Operation DragonReturn campaign is using spear-phishing and fake tax-filing lures to push remote access trojans into Indian taxpayer and finance environments, crea...

Latest development: 08.07.2026 03:00

Updated reporting on July 8, 2026 added Cyderes findings that Operation DragonReturn also uses fake websites impersonating the Indian Income Tax Department to deliver ZIP archives disguised as the common offline utility. The same chain deploys two implants, including a Gh0st RAT derivative that connects to kkxqbh[.]top on port 6666 and an AsyncRAT-family RAT that connects to ouewop[.]com on port 6351, while separate C2 channels, session-wide injection, and multiple initial access vectors improve persistence and resilience.

TA4922 expanded European phishing-and-malware campaign

Campaign
H score40 First: 04.06.2026 00:45 Last: 04.06.2026 00:45 Sources 1

How related: "It's worth mentioning here that this attack was documented in detail earlier this month by Seqrite Labs and Cyderes Howler Cell. Seqrite Labs is tracking the activity under the moniker Operation DragonReturn."

About this happening: TA4922 is a China-linked cybercrime campaign that now also uses the Cruciferra crypter, while continuing its income tax-themed phishing activity against Indian t...

SideCopy Operation XENOFISCAL spear-phishing campaign targeting Afghan finance entities

Campaign
H score25 First: 02.06.2026 12:05 Last: 02.06.2026 12:05 Sources 1

About this happening: The SideCopy-linked Operation XENOFISCAL spear-phishing campaign is targeting Afghanistan's Ministry of Finance and related provincial finance offices with Xeno RAT*...

Silver Fox tax-themed phishing campaign delivering ABCDoor and ValleyRAT

Campaign
H score36 First: 04.05.2026 14:57 Last: 04.05.2026 14:57 Sources 1

About this happening: Silver Fox is running a tax-themed phishing campaign that now targets India with Income Tax Department lures and delivers ValleyRAT (aka Winos 4.0). The campai...

Tax-season credential phishing and RMM malware campaign

Campaign
H score42 First: 30.03.2026 18:00 Last: 30.03.2026 18:00 Sources 1

About this happening: A tax-themed cyber campaign is using credential phishing, remote monitoring and management (RMM) tools, and fraud lures to target people handling financial data*...

Timeline

  1. 27.07.2026 13:51 2 articles · 2h ago

    Cruciferra-linked tax phishing targets Indian taxpayers and finance teams

    Initial Disclosure

    Proofpoint identified a China-linked cybercrime group using the Cruciferra crypter in income tax-themed phishing against Indian taxpayers, tax professionals, and corporate finance teams. One campaign is attributed to TA4922 and tracked by Seqrite Labs as Operation DragonReturn, with attacker-controlled landing pages and ZIP files used to deliver malware. Proofpoint says four such campaigns were identified between April and early June 2026, and the same tooling has also been observed in other campaigns delivering XWorm, AdaptixC2, and zgRAT.

    Show sources