Kaspersky Warns of SilverFox Hacker Group Targeting Indians with Fake Tax Emails
Fake income tax emails target Indians: Kaspersky warns of ‘SilverFox’ hacker attack
The Economic TimesImage: The Economic Times
Kaspersky has identified a cyber attack campaign by the SilverFox group, targeting Indians with fake emails resembling official communications from the Income Tax Department. The campaign, which began in December 2025, aims to trick recipients into downloading malicious files that can compromise sensitive data.
- 01The SilverFox group is behind a phishing campaign targeting Indians, Indonesia, South Africa, and Russia.
- 02Over 1,600 malicious emails were recorded within two months of the campaign's launch.
- 03The attacks utilize advanced techniques, including the deployment of a new Python-based backdoor named ABCDoor.
- 04Social engineering tactics are employed to exploit trust in official communications.
- 05Kaspersky recommends improving digital literacy and using cybersecurity solutions to mitigate risks.
Advertisement
In-Article Ad
In December 2025, Kaspersky, a global cybersecurity company, detected a phishing campaign led by the SilverFox threat group, targeting individuals and organizations in India with fake emails that closely resemble official communications from the Income Tax Department of India. This campaign aims to trick recipients into downloading malicious files that could compromise their devices and sensitive data. Kaspersky's analysis revealed that between January and February 2026, over 1,600 malicious emails were recorded, with similar campaigns also targeting entities in Indonesia, South Africa, and Russia. The emails were designed to appear as urgent tax audit notifications, prompting users to download an archive claiming to contain a list of tax violations. Upon clicking, users inadvertently downloaded a modified Rust-based loader that deploys the ValleyRAT backdoor, along with a new Python-based backdoor named ABCDoor, which has been part of the SilverFox arsenal since late 2024. This backdoor allows attackers to remotely control infected systems, stream victim screens, and access sensitive information. Kaspersky emphasizes the importance of social engineering in this attack, as the group exploits users' trust in official agencies. To protect against such threats, Kaspersky advises enhancing digital literacy, using automated email security solutions, and staying informed about emerging cyber threats.
Advertisement
In-Article Ad
This phishing campaign poses a significant risk to individuals and organizations in India, potentially leading to data breaches and financial losses.
Advertisement
In-Article Ad
Reader Poll
How concerned are you about phishing attacks targeting personal information?
Connecting to poll...
More about Kaspersky
Read the original article
Visit the source for the complete story.





