logo

Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia

ID: bf3168fc-4b84-5a5f-82b6-edda04d8253c

STIX ID: report--bf3168fc-4b84-5a5f-82b6-edda04d8253c

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Elizabeth Montalbano

...
...

Silver Fox, a China-linked threat actor, ran tax-themed phishing campaigns beginning December and expanding into Russia and India that delivered a previously undocumented Python backdoor called ABCDoor, ValleyRAT, and a customized RustSL loader; Kaspersky recorded ~1,600 malicious emails and details include persistence via Run keys and scheduled tasks, C2 over HTTPS using Socket.IO, multimonitor screen streaming via FFmpeg, remote control and data-theft capabilities, and forensic artifacts defenders can monitor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.