INTELLIGENT TECHNOLOGY
CYBERSECURITY
Kaspersky identifies new SilverFox campaign targeting companies in South Africa
Kaspersky’ s Global Research & Analysis Team( GReAT) has analysed several new waves of cyberattacks conducted by the SilverFox group, observed since December 2025.
The campaign targeted companies in South Africa – as well as India, Indonesia and Russia – across industrial, consulting, trade and transportation sectors.
The phishing emails were crafted to appear as official tax audit notifications or to prompt recipients to download an archive purportedly containing a‘ list of tax violations’.
By leveraging the perceived authority and urgency of communications from tax agencies, the threat actor aimed to persuade victims to download the file and trigger the attack chain. Between January and February alone, more than 1,600 malicious emails were recorded.
The group exploited users’ tendency to trust communications from official agencies.
The threat actor expanded its toolkit by deploying a new Python-based backdoor, dubbed ABCDoor, via the previously known ValleyRAT backdoor used in earlier attacks. ABCDoor was present in the APT arsenal from the end of 2024 and was used in attacks throughout 2025.
It enables attackers to upload and download files, and also to remotely control infected systems by streaming multiple victim screens simultaneously in near real time, accessing the clipboard and updating itself. In addition, a modified and previously undocumented version of RustSL was used to deliver ValleyRAT, first deployed by the threat actor in late December 2025.
Anton Kargin, Senior Security Researcher in Kaspersky GReAT, said:“ Social engineering played a key role in this campaign. The group exploited users’ tendency to trust communications from official agencies, such as tax authorities. At the same time, SilverFox employed a multi-stage delivery approach for the primary malicious payload and utilised multiple email addresses and domains. This increases the overall risk posed by such attacks, as it helps minimise the likelihood of detection and disruption across the attack chain.”
To stay safe, Kaspersky recommends organisations to:
• Regularly improve employees’ level of digital literacy through specialised courses or training programmes.
• Use solutions that can automatically block suspicious emails, scan password-protected archives and apply CDR technology.
• Provide cybersecurity specialists with access to cyberthreat intelligence to stay informed about the latest attacker techniques, tactics and procedures.
• Protect corporate infrastructure against a wide range of threats by using solutions that provide real-time protection, threat visibility, investigation and advanced response capabilities. •
28
INTELLIGENT CIO AFRICA www. intelligentcio. com