Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures
ID: 342efe02-7052-5492-a759-b2e877babd4b
STIX ID: report--342efe02-7052-5492-a759-b2e877babd4b
Feed Name: cybersecurityNews.com
Silver Fox, a China-linked threat actor, is targeting Indian organizations with tax-themed phishing PDFs that redirect victims to download a malicious executable (e.g., tax_affairs.exe). The campaign abuses a signed binary (Thunder.exe) via DLL hijacking (libexpat.dll), employs anti-analysis checks, decrypts an in-memory payload (box.ini) and ultimately deploys Valley RAT — a modular remote access tool that persists via registry-stored configuration and supports multiple C2 channels for credential harvesting, file transfer, and remote command execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
