Silver Fox Tax Audit Phishing Campaign Shifts from RATs to Python Stealers
ID: 7fd6212b-a5a7-5053-8d29-6cdcfa8b2c8d
STIX ID: report--7fd6212b-a5a7-5053-8d29-6cdcfa8b2c8d
Feed Name: GBHackers
This report details Silver Fox (Void Arachne) tax-themed phishing campaigns from 2025–early 2026 that evolved across three waves: initial ValleyRAT infections via malicious PDFs, later abuse of a legitimately signed Remote Monitoring and Management (RMM) binary to hide C2 parameters, and a final wave using a compiled Python stealer disguised as a WhatsApp backup utility; campaigns targeted organizations across China, Taiwan, Japan, Malaysia and broader South/Southeast Asia and included modular backdoors, signed-binary abuse, and bespoke stealers with observable IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
