logo

Silver Fox Targeting India Using Tax Themed Phishing Lures

ID: 15528c1d-b3ad-5739-9cdc-6ca19179d03b

STIX ID: report--15528c1d-b3ad-5739-9cdc-6ca19179d03b

Feed Name: CloudSEK Blog

Threat Score
85/100

Date Published: 2025-12-24

Date Updated: 2026-04-27

...
...

CloudSEK TRIAD describes an income-tax themed phishing campaign in India attributed to the Silver Fox APT that uses an NSIS installer and a signed Thunder.exe to load a malicious libexpat.dll, which disables services, decrypts and injects Donut-generated shellcode into explorer.exe, and deploys Valley RAT with registry-resident plugins and a three-tier C2 infrastructure; the report includes technical analysis, IOCs, MITRE ATT&CK mappings, and detection/mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.