Tax Audits and WhatsApp Clones: How “Silver Fox” is Redefining Cyber-Espionage in South Asia
ID: fdd3eb23-19d9-5483-917e-eccfec0f33bf
STIX ID: report--fdd3eb23-19d9-5483-917e-eccfec0f33bf
Feed Name: securityonline.info
Sekoia TDR details Silver Fox (Void Arachne), a China-based intrusion set active since 2022 that in 2025–2026 combined state-sponsored espionage and opportunistic financially motivated campaigns across Taiwan, Japan, Malaysia, India, Singapore, Thailand, Philippines and Indonesia; tactics include phishing PDFs delivering ValleyRAT, abuse of misconfigured RMM tools, and a Python stealer masquerading as WhatsApp, with recommended mitigations to audit RMMs, verify tax communications, and monitor suspicious Python executables in %TEMP%.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
