Tax Audit Phishing Campaign Tied to Silver Fox Shifts From RATs to Python Stealers
ID: 8bb92821-e63f-53c5-94f7-055c3dded72b
STIX ID: report--8bb92821-e63f-53c5-94f7-055c3dded72b
Feed Name: cybersecurityNews.com
Silver Fox (aka Void Arachne), active since at least 2022, executed three waves of tax-themed phishing campaigns in 2025–2026 across Taiwan, Japan, Malaysia, India, Indonesia, Singapore, Thailand, and the Philippines, evolving from ValleyRAT backdoors to a compiled Python stealer masquerading as a WhatsApp backup. The report documents delivery methods (malicious PDFs, fake tax sites, misconfigured RMM installers), C2 infrastructure (notably xqwmwru.top), host and network IOCs (python311.dll, C:\WhatsAppBackup\WhatsAppData.zip, whatsapp_backup.lock), and mitigation recommendations including user training, domain/C2 blocking, and endpoint monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
