• About us
  • Contact us
Thursday, June 4, 2026
No 1 epaper in Sri Lanka
  • News
  • Politics
  • Sports
  • Foreign
  • Entertainment
  • Business
  • Political Analysis
  • Inside Politics
  • EPAPERPDF
  • සිංහලSINHALA
No Result
View All Result
  • News
  • Politics
  • Sports
  • Foreign
  • Entertainment
  • Business
  • Political Analysis
  • Inside Politics
  • EPAPERPDF
  • සිංහලSINHALA
No Result
View All Result
Mawratanews.lk | Sri Lanka Latest Sinhala News and Headlines
No Result
View All Result
Home Business

Kaspersky identified a new SilverFox campaign targeting Indian and Indonesian companies

May 6, 2026
in Business
Reading Time: 11 mins read
A A
Kaspersky identified a new SilverFox campaign targeting Indian and Indonesian companies
Share on FacebookShare on Twitter

The APT campaign involved disguising malicious files as documents related to tax violations. Upon infection, attackers could gain remote access to affected devices and exfiltrate sensitive organizational data.
Kaspersky Global Research & Analysis Team (GReAT) analyzed several new waves of cyberattacks conducted by the SilverFox group, observed since December 2025. The campaign targeted companies in India, Indonesia, South Africa and Russia across industrial, consulting, trade and transportation sectors.
The phishing emails were crafted to appear as official tax audit notifications or to prompt recipients to download an archive purportedly containing a “list of tax violations.” By leveraging the perceived authority and urgency of communications from tax agencies, the threat actor aimed to persuade victims to download the file and trigger the attack chain. Between January and February alone, more than 1,600 malicious emails were recorded.
The threat actor expanded its toolkit by deploying a new Python-based backdoor, dubbed as ABCDoor, via the previously known ValleyRAT backdoor used in earlier attacks. ABCDoor was present in the APT arsenal from the end of 2024 and was used in attacks throughout 2025. It enables attackers to upload and download files, and also to remotely control infected systems by streaming multiple victim screens simultaneously in near real time, accessing the clipboard, and updating itself. In addition, a modified and previously undocumented version of RustSL was used to deliver ValleyRAT, first deployed by the threat actor in late December 2025.
“Social engineering played a key role in this campaign. The group exploited users’ tendency to trust communications from official agencies, such as tax authorities. At the same time, SilverFox employed a multi-stage delivery approach for the primary malicious payload and utilized multiple email addresses and domains. This increases the overall risk posed by such attacks, as it helps minimize the likelihood of detection and disruption across the attack chain,” says Anton Kargin, senior security researcher in Kaspersky GReAT.
Previously, SilverFox targeted enterprises in Asia in sectors including telecommunications, energy, logistics and finance. Read the full report on Securelist.com to learn more about the APT new campaign and its toolset.
To stay safe Kaspersky recommends that organizations: Regularly improve employees’ level of digital literacy. This can be achieved through specialized courses or training programs, such as the Kaspersky Automated Security Awareness Platform. Use a solution that can automatically block suspicious emails, scan password-protected archives and apply CDR technology, such as Kaspersky Security for Mail Server. Provide cybersecurity specialists with access to cyber threat intelligence, for example through Threat Intelligence services, so they can stay informed about the latest attacker techniques, tactics and procedures. Protect corporate infrastructure against a wide range of threats by using solutions from the Kaspersky Next product line that provide real-time protection, threat visibility, investigation and advanced response capabilities.


Photo Caption:

  1. Phishing email distributed to victims in India
Share51Tweet32Send
Previous Post

Work to Commence on Six Important Socio-Economic Projects in Eastern Province through Indian Grant Assistance

Next Post

ACAP unveils strategic business transformation; sets sight on a new frontier of investments into Sri Lanka

MORE NEWS

Kaspersky detected more than 92,000 malware attacks disguised as AI services in 2026
Business

Kaspersky detected more than 92,000 malware attacks disguised as AI services in 2026

June 3, 2026
Bridging Sri Lanka’s Internship Crisis: National Virtual Internship Platform Launches
Business

Bridging Sri Lanka’s Internship Crisis: National Virtual Internship Platform Launches

June 3, 2026
AI and Data Analytics Summit 2026 Drives the Nation’s Digital Future
Business

AI and Data Analytics Summit 2026 Drives the Nation’s Digital Future

June 3, 2026
People’s Bank Conducts Financial Literacy Programme for Entrepreneurs in Weboda
Business

People’s Bank Conducts Financial Literacy Programme for Entrepreneurs in Weboda

June 3, 2026
Despite robust security measures, credential abuse techniques remain the most effective attack method
Business

Despite robust security measures, credential abuse techniques remain the most effective attack method

May 30, 2026
ComBank pioneers state-of-the-art 3DS authentication for UnionPay cardholders
Business

ComBank pioneers state-of-the-art 3DS authentication for UnionPay cardholders

May 30, 2026
Load More

One of the best Sri Lanka Latest News Website and Sinhala language newspaper with Sunday editions, published by Free Media Independent Networks Pvt Ltd.

  • About us
  • Contact us

Copyright © 2019–2025 Free Media Independent Networks Pvt Ltd. All Rights Reserved. Developed by Turn Global.

No Result
View All Result
  • News
  • Politics
  • Sports
  • Foreign
  • Entertainment
  • Business
  • Political Analysis
  • Inside Politics
  • EPAPER
  • සිංහල

Copyright © 2019–2025 Free Media Independent Networks Pvt Ltd. All Rights Reserved. Developed by Turn Global.