logo

Tax Audit Phishing Campaign Tied to Silver Fox Shifts From RATs to Python Stealers

ID: 8bb92821-e63f-53c5-94f7-055c3dded72b

STIX ID: report--8bb92821-e63f-53c5-94f7-055c3dded72b

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-26

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Silver Fox (aka Void Arachne), active since at least 2022, executed three waves of tax-themed phishing campaigns in 2025–2026 across Taiwan, Japan, Malaysia, India, Indonesia, Singapore, Thailand, and the Philippines, evolving from ValleyRAT backdoors to a compiled Python stealer masquerading as a WhatsApp backup. The report documents delivery methods (malicious PDFs, fake tax sites, misconfigured RMM installers), C2 infrastructure (notably xqwmwru.top), host and network IOCs (python311.dll, C:\WhatsAppBackup\WhatsAppData.zip, whatsapp_backup.lock), and mitigation recommendations including user training, domain/C2 blocking, and endpoint monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.