Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures

## Cybersecurity: Silver Fox Phishing Campaign

Cybersecurity: Silver Fox Phishing Campaign

Chinese threat actors known as Silver Fox are targeting Indian organizations through advanced phishing campaigns. These campaigns simulate legitimate income tax documents to deceive recipients.

The attack involves emails that appear to come from the Income Tax Department, urging users to download a malicious executable disguised as a tax-related file. Upon execution, the victim is directed to a command-and-control server, beginning an infection process designed to bypass security measures and maintain persistent system access.

The attack initiates with a deceptive email that includes a PDF attachment. This PDF, when opened, leads to a malicious website, which downloads a file named "tax_affairs.exe".

This initial file acts as a loader for multiple malware stages, each crafted to conceal its true intent while ensuring sustained access to the victim's system. This attack highlights the utilization of socially engineered documents and trusted file formats to bypass traditional security controls.

CloudSEK analysts identified the malware, correcting previous misattributions to other threat groups. Accurate threat attribution is crucial for deploying the right defensive measures against specific adversaries.

Understanding the attack's origin allows security teams to anticipate tactics and implement tailored countermeasures against Silver Fox's operational patterns.

Chinese threat actors known as Silver Fox are targeting Indian organizations through advanced phishing campaigns.
Henry Dalton · Thehackingpost

The infection technique employs DLL hijacking to activate its payload. The initial stage drops a legitimate executable, Thunder.exe, developed by Xunlei, a Chinese software company.

A malicious DLL file named libexpat.dll is placed in the same directory. When Thunder.exe runs, Windows loads this fake DLL, executing the attacker's code while appearing legitimate.

The malicious DLL includes anti-analysis capabilities to detect security tools and sandboxes . It checks system resources, terminating if analysis tools are detected, to avoid detection.

Once the system passes these checks, the DLL disables Windows Update services and loads an encrypted file named box.ini from the temporary directory. This payload is decrypted using hardcoded cryptographic keys and executed as raw machine code, leaving minimal traces.

Advertisement

The final payload is Valley RAT, a remote access tool establishing a command and control infrastructure. It employs a three-tier failover system to maintain communication with attacker servers, switching between primary, secondary, and tertiary centers if necessary.

The malware stores its configuration in the Windows registry as binary data, allowing updates to command and control addresses without reinstalling the malware. It supports multiple communication protocols, including HTTP, HTTPS, and raw TCP sockets, complicating network filtering efforts.

Once installed, Valley RAT can execute commands, capture keystrokes, harvest credentials , transfer files, and deploy additional malicious modules as required. Its modular architecture enables customization per infection, adapting to the target's role and value within the organization, posing significant threats to Indian enterprises.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories