logo

Silver Fox Tax Audit Phishing Campaign Shifts from RATs to Python Stealers

ID: 7fd6212b-a5a7-5053-8d29-6cdcfa8b2c8d

STIX ID: report--7fd6212b-a5a7-5053-8d29-6cdcfa8b2c8d

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-03-26

Date Updated: 2026-06-18

Author: Mayura Kathir

...
...

This report details Silver Fox (Void Arachne) tax-themed phishing campaigns from 2025–early 2026 that evolved across three waves: initial ValleyRAT infections via malicious PDFs, later abuse of a legitimately signed Remote Monitoring and Management (RMM) binary to hide C2 parameters, and a final wave using a compiled Python stealer disguised as a WhatsApp backup utility; campaigns targeted organizations across China, Taiwan, Japan, Malaysia and broader South/Southeast Asia and included modular backdoors, signed-binary abuse, and bespoke stealers with observable IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.