Physical AI HBM Smart Factory SDV AIoT Power Semicon 특수 가스 정정·반론보도 모음 e4ds plus

Kaspersky Detects 'SilverFox' APT Disguised as Tax Notices

Google 우선 소스 기사입력2026.06.23 09:17

Over 1,600 malicious emails confirmed in January-February targeting companies in four countries including India and Indonesia

Kaspersky has detected 'SilverFox,' an APT attack that distributes malicious files disguised as tax violation notices from tax authorities. It is reported that if an infection occurs, attackers can gain remote access to the affected device and leak an organization's sensitive data to the outside.


Kaspersky announced on the 23rd that its Global Research and Analysis Team (GReAT) has analyzed several new attack campaigns by the SilverFox hacker group observed since December 2025.

This campaign was conducted targeting companies in the industrial, consulting, trade, and transportation sectors of India, Indonesia, South Africa, and Russia.

Phishing emails were designed to disguise themselves as official tax audit notices or to induce recipients to download compressed files containing a 'list of tax violations.'

Attackers exploited the authority and urgency of tax authorities to induce file downloads and the execution of attack chains, and more than 1,600 malicious emails were detected between January and February alone.

Threat actors through the ValleyRAT backdoor used in previous attacks Expanded the toolset by distributing the Python-based backdoor 'ABCDoor'.

ABCDoor was included in the attack tool suite starting in late 2024 and was used throughout 2025.

This backdoor is reported to be equipped with remote control functions of the infected system, such as file uploading and downloading, real-time streaming of multiple victims' screens, and clipboard access, as well as self-updating capabilities.

In addition, a previously unreleased modified RustSL variant was first introduced in late December 2025 and used for ValleyRAT delivery.

Anton Kargin, a senior security researcher at GReAT, said, “Social engineering played a key role in this campaign, and attackers exploited user trust in official agencies such as tax authorities,” adding, “They used multi-stage delivery methods and multiple email addresses and domains to lower the likelihood of detection and blocking.”

Lee Hyo-eun, Country Manager of Kaspersky Korea, said, “Korea has a high dependence on e-government and tax systems, creating an environment where phishing impersonating tax authorities can operate effectively,” adding, “The tactics used by SilverFox in India and Indonesia can be easily replicated domestically, so we must strengthen both employee security awareness training and Endpoint Detection and Response (EDR) capabilities.”