Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia
ID: bf3168fc-4b84-5a5f-82b6-edda04d8253c
STIX ID: report--bf3168fc-4b84-5a5f-82b6-edda04d8253c
Feed Name: Dark Reading
Silver Fox, a China-linked threat actor, ran tax-themed phishing campaigns beginning December and expanding into Russia and India that delivered a previously undocumented Python backdoor called ABCDoor, ValleyRAT, and a customized RustSL loader; Kaspersky recorded ~1,600 malicious emails and details include persistence via Run keys and scheduled tasks, C2 over HTTPS using Socket.IO, multimonitor screen streaming via FFmpeg, remote control and data-theft capabilities, and forensic artifacts defenders can monitor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
