Friday, September 11, 2026

Silver Fox Tax Audit Phishing Campaign Shifts from RATs to Python Stealers

Threat intelligence teams have tracked Silver Fox (also known as Void Arachne), a China-based intrusion set that sits at the intersection of financially motivated cybercrime and APT-style espionage.

Originally associated with large-scale, profit-driven campaigns, the group has steadily adopted more advanced tradecraft, including modular backdoors, rootkits, and the exploitation of vulnerable drivers.

TDR’s monitoring between 2025 and early 2026 highlights a three-wave evolution tied to tax-themed phishing operations across South Asia.  

In the first wave, Silver Fox leaned on its flagship ValleyRAT (aka Winos) backdoor, delivered through malicious PDF attachments that impersonated national tax authorities.  

According to the report, Recent activity shows Silver Fox retooling again, this time moving away from traditional RAT-heavy chains toward misused remote monitoring tools and a custom Python stealer masquerading as a WhatsApp utility.

These lures rode on real-world communications around Taiwan’s profit-seeking enterprise tax audit window, increasing credibility and click-through rates.

Silver Fox Tax Audit Phishing

Victims received short, official-looking emails with a PDF that mimicked a Ministry of Finance announcement; opening the file triggered a multi-stage chain culminating in ValleyRAT.

Technically, the initial infection relied on a PDF with a hidden clickable annotation that fetched a ZIP archive from Tencent Cloud (myqcloud) infrastructure.

The archive contained a DLL (python311.dll) used as a loader and an executable that ultimately executed ValleyRAT, whose configuration was retrieved from a decoy JPG stored under the public user directory.

From there, ValleyRAT modular plugins enabled keystroke logging, remote control, security bypass, and data exfiltration, supporting both financial abuse and potential intelligence collection.

This wave primarily impacted entities in China, Taiwan, and later Japan and Malaysia, illustrating how a single lure theme was repurposed for multiple geographies.

Phishing website impersonating Indonesia Tax entity (Source : sekoia).
Phishing website impersonating Indonesia Tax entity (Source : sekoia).

By mid-December 2025, a second wave signaled a notable operational pivot. Instead of delivering ValleyRAT directly, Silver Fox deployed a legitimate Chinese Remote Monitoring and Management (RMM) tool signed by SyncFutureTec Company Limited, obtained via tax-themed phishing websites linked from emails.

The RMM installer’s filename embedded an IPv4 address followed by “ClientSetup.exe,” with the IP string acting as the command-and-control endpoint, allowing attackers to pass C2 parameters without modifying the signed binary.

This misconfiguration abuse preserved the tool’s digital signature, helped evade static trust controls, and expanded targeting to Malaysia, the Philippines, Thailand, Indonesia, Singapore, and India.

Geographic distribution (Source : sekoia).
Geographic distribution (Source : sekoia).

The third and latest wave, observed in February 2026, replaced the RMM payload with a compiled Python stealer hidden behind a fake WhatsApp backup application.

Python Stealers: A Growing Threat

The phishing site, localized in Malay and hosted on infrastructure in the 154.201.87[.]0/24 range, delivered an executable that collected browser and application artefacts and uploaded them to a C2 at xqwmwru[.]top using a custom User-Agent string “WhatsAppBackup/1.0.”

Artefacts such as “C:\WhatsAppBackup\WhatsAppData.zip” and a temporary lock file signpost compromised hosts, while the C2 front-end imitates WhatsApp Web to blend malicious traffic into expected patterns.

Stolen credentials can then fuel business email compromise, account takeover, and downstream fraud.

Across all three waves, the constant is Silver Fox use of culturally and bureaucratically familiar tax or payroll lures rather than any specific malware family.

TDR assesses that the ValleyRAT and HoldingHands toolkit remains available for higher-value, espionage-leaning operations, while RMM abuse and the Python stealer better fit scalable, profit-oriented campaigns.

This dual-track posture combining opportunistic financial crime with selective APT-like intrusions mirrors a broader 2025–2026 trend where the boundary between state-linked espionage and cybercrime continues to blur.

For defenders in South Asia and beyond, spotting tax-season phishing tied to remote tools or “WhatsApp backup” utilities may now be the clearest early warning of Silver Fox activity.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News