{"id":80466,"date":"2026-04-30T14:49:13","date_gmt":"2026-04-30T13:49:13","guid":{"rendered":"https:\/\/www.intelligentcio.com\/africa\/?p=80466"},"modified":"2026-04-30T14:49:14","modified_gmt":"2026-04-30T13:49:14","slug":"kaspersky-identifies-new-silverfox-campaign-targeting-companies-in-south-africa","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2026\/04\/30\/kaspersky-identifies-new-silverfox-campaign-targeting-companies-in-south-africa\/","title":{"rendered":"Kaspersky identifies new SilverFox campaign targeting companies in South Africa"},"content":{"rendered":"\n<p>Kaspersky\u2019s Global Research &amp; Analysis Team (GReAT) has&nbsp;analysed&nbsp;several new waves of cyberattacks conducted by the&nbsp;SilverFox&nbsp;group,&nbsp;observed&nbsp;since December 2025. The campaign targeted companies in South Africa&nbsp;\u2013&nbsp;as well as&nbsp;India,&nbsp;Indonesia&nbsp;and Russia&nbsp;\u2013&nbsp;across industrial, consulting,&nbsp;trade&nbsp;and transportation sectors.&nbsp;<\/p>\n\n\n\n<p>The phishing emails were crafted to appear as official tax audit notifications or to prompt recipients to download an archive&nbsp;purportedly&nbsp;containing&nbsp;a&nbsp;\u2018list of tax&nbsp;violations\u2019.&nbsp;By&nbsp;leveraging&nbsp;the perceived authority and urgency of communications from tax agencies, the&nbsp;threat&nbsp;actor aimed to persuade victims to download the file and trigger the attack chain.&nbsp;Between January and February alone, more than 1,600 malicious emails were recorded.&nbsp;<\/p>\n\n\n\n<p>The threat actor expanded its toolkit by deploying a new Python-based backdoor, dubbed&nbsp;ABCDoor, via the previously known&nbsp;ValleyRAT&nbsp;backdoor used in earlier attacks.&nbsp;ABCDoor&nbsp;was present in the APT arsenal from the end of 2024 and was used in attacks throughout 2025. It enables attackers to upload and download files,&nbsp;and also&nbsp;to remotely control infected systems by streaming multiple victim screens simultaneously in near real time, accessing the clipboard and updating itself. In addition, a modified and previously undocumented version of&nbsp;RustSL&nbsp;was used to deliver&nbsp;ValleyRAT, first deployed by the threat actor in late December 2025.&nbsp;<\/p>\n\n\n\n<p>Anton Kargin, Senior Security Researcher&nbsp;in&nbsp;Kaspersky&nbsp;GReAT,&nbsp;said:&nbsp;\u201cSocial engineering played a key role in this campaign.&nbsp;The group exploited users\u2019 tendency to trust communications from official agencies, such as tax authorities. At the same time,&nbsp;SilverFox&nbsp;employed a multi-stage delivery approach for the primary malicious payload and&nbsp;utilised&nbsp;multiple email addresses and domains. This increases the overall risk posed by such attacks, as it helps&nbsp;minimise&nbsp;the likelihood of detection and disruption across the attack chain.\u201d&nbsp;<\/p>\n\n\n\n<p>To stay safe, Kaspersky recommends&nbsp;organisations&nbsp;to:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Regularly improve\u00a0employees\u2019 level of digital literacy through\u00a0specialised\u00a0courses or training\u00a0programmes.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use solutions that can automatically block suspicious emails, scan password-protected\u00a0archives\u00a0and apply CDR technology.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Provide\u00a0cybersecurity specialists with access to cyber threat intelligence to stay informed about the latest attacker techniques,\u00a0tactics\u00a0and procedures.\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Protect corporate infrastructure against a wide range of threats by using solutions that provide real-time protection, threat visibility,\u00a0investigation\u00a0and advanced response capabilities.\u00a0<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky\u2019s Global Research &amp; Analysis Team (GReAT) has&nbsp;analysed&nbsp;several new waves of cyberattacks conducted by the&nbsp;SilverFox&nbsp;group,&nbsp;observed&nbsp;since December 2025. The campaign targeted companies in South Africa&nbsp;\u2013&nbsp;as well as&nbsp;India,&nbsp;Indonesia&nbsp;and Russia&nbsp;\u2013&nbsp;across industrial, consulting,&nbsp;trade&nbsp;and transportation sectors.&nbsp; The phishing emails were crafted to appear as official tax audit notifications or to prompt recipients to download an archive&nbsp;purportedly&nbsp;containing&nbsp;a&nbsp;\u2018list of tax&nbsp;violations\u2019.&nbsp;By&nbsp;leveraging&nbsp;the perceived authority [&hellip;]<\/p>\n","protected":false},"author":2418,"featured_media":80467,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15417,9059,13],"tags":[388,9201,226,101,1415,453,849],"class_list":["post-80466","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-south-africa","category-top-stories","tag-cybersecurity","tag-great","tag-kaspersky","tag-malware","tag-phishing","tag-south-africa","tag-threat-intelligence"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/80466","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/2418"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=80466"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/80466\/revisions"}],"predecessor-version":[{"id":80468,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/80466\/revisions\/80468"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/80467"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=80466"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=80466"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=80466"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}