Silver Fox Cyber Campaigns Show Shift Toward Dual Espionage
ID: a2606699-16cd-5785-8f35-98aae9dfc9b4
STIX ID: report--a2606699-16cd-5785-8f35-98aae9dfc9b4
Feed Name: Infosecurity Magazine (News)
**Executive summary:** Sekoia attributes a series of 2025–2026 campaigns to the Silver Fox group that evolved from ValleyRAT delivered via malicious PDF/DLL side‑loading to phishing websites and a custom Python credential stealer disguised as WhatsApp, using tax- and payroll-themed lures, SEO poisoning, and remote management tools to target organizations across Taiwan, Japan, Malaysia, India, Indonesia, Singapore, Thailand and the Philippines, indicating both espionage and profit-driven objectives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
