Kaspersky GReAT Report SilverFox Campagins aimed at Indian and Indonesian Companies

The Kaspersky GReAT Report SilverFox highlights a growing pattern where attackers are no longer breaking systems directly, but quietly gaining access through trust. The campaign used tax-related emails to trick users into opening malicious files disguised as official documents.
This form of Income Tax Audit Phishing India shows how routine communication is now being weaponised, making it harder for employees to distinguish between legitimate and malicious interactions in everyday workflows.
A targeted approach with familiar themes
The campaign, active since December 2025, focused on sectors such as industrial, consulting, trade and transportation across multiple regions, including India. Attackers sent emails that appeared to carry lists of tax violations or audit notices, pushing users to download infected files.
This SilverFox APT Indian Tax Phishing strategy relied heavily on urgency and authority, exploiting the natural tendency of users to respond quickly to compliance-related communication without questioning its authenticity.
The rise of multi-stage attack chains
What makes this campaign more complex is its layered delivery model. The attackers used multiple email addresses and domains to distribute over 1,600 malicious emails within a short period, reducing the chances of detection across systems.
This approach reflects a broader shift where phishing is no longer a single event, but part of a coordinated chain designed to gradually bypass security controls and establish deeper access within enterprise environments.
Remote screen streaming malware changes the game
A key component of the attack was the deployment of a Python-based backdoor known as ABCDoor, delivered through existing tools like ValleyRAT. Once activated, it allowed attackers to gain extensive control over infected systems.
The use of Remote Screen Streaming Malware is particularly concerning, as it enables real-time monitoring of multiple screens, access to clipboard data, and continuous system interaction, effectively turning compromised devices into live surveillance points.
Expanding toolsets signal evolving threats
The campaign also introduced a modified version of RustSL, adding another layer to the attack infrastructure. These evolving toolsets show that threat actors are investing in flexibility and persistence rather than one-time breaches.
By combining known backdoors with new delivery techniques, attackers are creating adaptable frameworks that can operate across different environments with minimal disruption to their activities.
What organisations need to rethink
The findings suggest that traditional security measures alone are no longer enough. The gap lies in user awareness, credential protection, and visibility into system activity, especially when threats originate from seemingly trusted sources.
As highlighted in the Kaspersky GReAT Report SilverFox, organisations need to focus on strengthening internal guardrails, improving employee awareness, and adopting tools that can detect suspicious behaviour across the entire attack chain. This campaign is a reminder that modern cyberattacks are less about force and more about access. The weakest link is no longer the system, but the moment a user decides to trust what they see.
Read More:
Zoho State of Workforce Password Security reveals risky gap in Indian Firms
ASIRT TechDay 136: Empowering Mumbai SIs with MSP growth strategy






