Silver Fox Targeting India Using Tax Themed Phishing Lures
Dec. 26, 2025, 10:05 a.m.
Description
A sophisticated campaign by the Chinese APT group Silver Fox is targeting Indian entities with authentic-looking Income Tax phishing lures. The attack leverages a complex kill chain involving DLL hijacking and the modular Valley RAT to ensure persistence. The campaign uses a multi-stage infection process, starting with a malicious email containing a PDF decoy. The payload is delivered through an NSIS installer, which drops a legitimate Thunder.exe binary and a malicious libexpat.dll for DLL hijacking. The final stage involves the Valley RAT, which uses a two-stage configuration loading mechanism and implements a 3-tier C2 communication loop. The RAT's modular plugin architecture allows for dynamic capability extension and persistence through registry-based storage.
Tags
Date
- Created: Dec. 24, 2025, 9:10 p.m.
- Published: Dec. 24, 2025, 9:10 p.m.
- Modified: Dec. 26, 2025, 10:05 a.m.
Indicators
- 068e49e734c2c7be4fb3f01a40bb8beb2d5f4677872fabbced7741245a7ea97c
- fa388a6cdd28ad5dd83acd674483828251f21cbefaa801e839ba39af24a6ac19
- 77ea62ff74a66f61a511eb6b6edac20be9822fa9cc1e7354a8cd6379c7b9d2d2
- f74017b406e993bea5212615febe23198b09ecd73ab79411a9f6571ba1f94cfa
- 103.20.195.147
- 160.124.9.103
- 45.207.231.94
- 45.207.231.107
Additional Informations
- Finance
- Government
- ggwk.cc
- gov-a.club
- swjc2025bjkb.cn
- gov-a.work
- govk.club
- hhiioo.work
- dingtalki.cn
- xzghjec.com
- hhimm.work
- gov-c.club
- kkyui.club
- itdd.club
- 2025swmm.cn
- gov-a.fit
- gvo-b.club
- b.yuxuanow.top
- hhiioo.cn
- India