Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

A sophisticated hacking campaign, suspected of originating from China, has compromised Indian businesses and individuals by using a fake tax filing utility to deploy the DcRAT malware. The hackers’ tactics exploit a vulnerability in Microsoft’s Windows operating system, leveraging AI-powered threat analysis to evade detection.

The attackers created a convincing fake tax filing tool, which was sent to victims via email or downloaded from a compromised website. Once installed on a victim’s device, the malware allowed the hackers to gain remote access and control over the computer. The DcRAT malware is designed to steal sensitive data, including financial information, login credentials, and other personal details.

To deploy the malware, the attackers exploited a vulnerability in Microsoft’s Windows operating system, specifically the CVE-2022-34713 zero-day flaw. This vulnerability allows an attacker to execute arbitrary code on a vulnerable system without requiring user interaction. The hackers used AI-powered tools to analyze and exploit this vulnerability, making it difficult for traditional security systems to detect.

The hacking campaign has compromised Indian businesses and individuals, with reports suggesting that the attackers are targeting specific industries, including finance and government. The use of a fake tax filing utility is particularly concerning, as it takes advantage of the trust victims have in official documents and institutions. This tactic is often used by hackers to bypass security measures and gain access to sensitive systems.

The hacking campaign highlights the growing threat posed by AI-powered attacks and the need for organizations to adopt more sophisticated cybersecurity strategies. As AI becomes increasingly prevalent in cybersecurity, so too do the tactics employed by attackers. To stay ahead of these threats, businesses must invest in AI-powered security tools and training programs that can detect and respond to advanced threats.

In light of this incident, it’s essential for individuals and organizations to be cautious when downloading or installing software from unknown sources. Verify the authenticity of any utility or tool before using it, and ensure that your operating system is up-to-date with the latest security patches. Furthermore, implement robust cybersecurity measures, such as multi-factor authentication and regular backups, to minimize the risk of data loss in case of a breach.


Source: The Hacker News — 2026-07-06