EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJULY 6, 20263 min read

Security Briefing | July 06, 2026 - China-Nexus Campaign Hits Indian Taxpayers with DcRAT, New Cross-Platform QuimaRAT MaaS, Bad Epoll PoC Now Public

A China-linked threat cluster dubbed Operation DragonReturn is using spear-phishing emails impersonating India's Income Tax Department to deliver the DcRAT remote access trojan. Researchers identified QuimaRAT, a new Java-based cross-platform RAT sold as a service for $150 to $1,200 targeting Windows, Linux, and macOS. Meanwhile a public proof-of-concept exploit has been released for the Linux Bad Epoll privilege escalation vulnerability, significantly raising the risk for unpatched systems.

By EACA Summit Content Team

Security Briefing | July 06, 2026 - China-Nexus Campaign Hits Indian Taxpayers with DcRAT, New Cross-Platform QuimaRAT MaaS, Bad Epoll PoC Now Public

1. Suspected China-Nexus Hackers Target Indian Taxpayers with DcRAT

A threat cluster linked to China, tracked as Operation DragonReturn, is using spear-phishing emails impersonating the Indian Income Tax Department to deliver the DcRAT remote access trojan. The campaign targets taxpayers, tax professionals, and corporate finance teams to steal sensitive data.

Verified Facts

  • Campaign identified by Seqrite Labs as Operation DragonReturn
  • Spear-phishing emails impersonate the Income Tax Department of India
  • Delivers DcRAT remote access trojan
  • Targets Indian taxpayers, tax professionals, and corporate finance teams

Evidence

  • Seqrite Labs report on Operation DragonReturn

Impact

Organizations in India, especially finance and tax sectors, should enhance email security and user awareness to prevent credential theft and data exfiltration.

Confidence Level: High

Sources The Hacker News

2. New Java-Based QuimaRAT MaaS Targets Windows, Linux, and macOS

Linux, macOS, and Windows server stacks connected by glowing data streams to a central dark command node, representing a cross-platform Java-based remote access trojan targeting all three operating systems.

Researchers at LevelBlue have identified a new Java-based remote access trojan called QuimaRAT, sold as a malware-as-a-service (MaaS) for $150 to $1,200. It is cross-platform, targeting Windows, Linux, and macOS environments.

Verified Facts

  • QuimaRAT is a Java-based RAT
  • Advertised as MaaS with pricing from $150 (1 month) to $1,200 (lifetime)
  • Targets Windows, Linux, and macOS
  • Identified by LevelBlue

Evidence

  • LevelBlue research report

Impact

Defenders should monitor for Java-based malware and implement cross-platform endpoint detection controls, as this RAT lowers the barrier for attackers targeting diverse environments.

Confidence Level: High

Sources The Hacker News

3. Bad Epoll Update: Public Proof-of-Concept Exploit Released for Linux Root Access Vulnerability

A proof-of-concept exploit has now been publicly released for the Linux Bad Epoll kernel vulnerability (first reported July 04), which allows local privilege escalation to root. The availability of working exploit code significantly raises the risk for all unpatched Linux systems.

Verified Facts

  • Proof-of-concept exploit code released for Linux Bad Epoll vulnerability
  • Vulnerability allows local privilege escalation to root
  • SecurityWeek urges organizations to patch immediately

Evidence

  • SecurityWeek article
  • Proof-of-concept exploit code

Impact

Linux systems are at increased risk of local privilege escalation. Administrators should prioritize patching and monitor for exploitation attempts, as the public PoC lowers the barrier for attackers significantly.

Confidence Level: High

Sources SecurityWeek

All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings