logo

Tax Audits and WhatsApp Clones: How “Silver Fox” is Redefining Cyber-Espionage in South Asia

ID: fdd3eb23-19d9-5483-917e-eccfec0f33bf

STIX ID: report--fdd3eb23-19d9-5483-917e-eccfec0f33bf

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-03-29

Date Updated: 2026-04-23

Author: Ddos

...
...

Sekoia TDR details Silver Fox (Void Arachne), a China-based intrusion set active since 2022 that in 2025–2026 combined state-sponsored espionage and opportunistic financially motivated campaigns across Taiwan, Japan, Malaysia, India, Singapore, Thailand, Philippines and Indonesia; tactics include phishing PDFs delivering ValleyRAT, abuse of misconfigured RMM tools, and a Python stealer masquerading as WhatsApp, with recommended mitigations to audit RMMs, verify tax communications, and monitor suspicious Python executables in %TEMP%.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.