Silver Fox Targeting India Using Tax Themed Phishing Lures

Dec. 26, 2025, 10:05 a.m.

Description

A sophisticated campaign by the Chinese APT group Silver Fox is targeting Indian entities with authentic-looking Income Tax phishing lures. The attack leverages a complex kill chain involving DLL hijacking and the modular Valley RAT to ensure persistence. The campaign uses a multi-stage infection process, starting with a malicious email containing a PDF decoy. The payload is delivered through an NSIS installer, which drops a legitimate Thunder.exe binary and a malicious libexpat.dll for DLL hijacking. The final stage involves the Valley RAT, which uses a two-stage configuration loading mechanism and implements a 3-tier C2 communication loop. The RAT's modular plugin architecture allows for dynamic capability extension and persistence through registry-based storage.

Date

  • Created: Dec. 24, 2025, 9:10 p.m.
  • Published: Dec. 24, 2025, 9:10 p.m.
  • Modified: Dec. 26, 2025, 10:05 a.m.

Indicators

  • 068e49e734c2c7be4fb3f01a40bb8beb2d5f4677872fabbced7741245a7ea97c
  • fa388a6cdd28ad5dd83acd674483828251f21cbefaa801e839ba39af24a6ac19
  • 77ea62ff74a66f61a511eb6b6edac20be9822fa9cc1e7354a8cd6379c7b9d2d2
  • f74017b406e993bea5212615febe23198b09ecd73ab79411a9f6571ba1f94cfa
  • 103.20.195.147
  • 160.124.9.103
  • 45.207.231.94
  • 45.207.231.107

Attack Patterns

Additional Informations

  • Finance
  • Government
  • ggwk.cc
  • gov-a.club
  • swjc2025bjkb.cn
  • gov-a.work
  • govk.club
  • hhiioo.work
  • dingtalki.cn
  • xzghjec.com
  • hhimm.work
  • gov-c.club
  • kkyui.club
  • itdd.club
  • 2025swmm.cn
  • gov-a.fit
  • gvo-b.club
  • b.yuxuanow.top
  • hhiioo.cn
  • India