Tax Phishing Delivers Swappable Malware in India and Russia
Silver Fox is using tax-themed lures to turn a simple phishing email into a modular delivery system. The standard response misses the point: the lure is stable, but the payload can be swapped without changing the campaign’s outward shape.
Kaspersky says the group sent more than 1,600 malicious emails between early January and early February, targeting industrial, consulting, retail, and transportation organizations in India and Russia. The emails delivered a public Rust-based loader that fetched ValleyRAT, and in some cases a new ValleyRAT plugin that loaded the previously undocumented ABCDoor backdoor.
That modular setup makes the campaign harder to read from the lure alone. It also means defenders cannot assume the same attachment or payload will recur in the next wave.