{"id":646153,"date":"2026-05-10T06:59:46","date_gmt":"2026-05-10T04:59:46","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=646153"},"modified":"2026-05-10T07:11:01","modified_gmt":"2026-05-10T05:11:01","slug":"hacker-group-targeted-companies-in-south-africa-using-fake-sars-notifications","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/646153-hacker-group-targeted-companies-in-south-africa-using-fake-sars-notifications.html","title":{"rendered":"Hacker group targeted companies in South Africa using fake SARS notifications"},"content":{"rendered":"\n<p>Hacker group SilverFox has been linked to a campaign in South Africa that used fake notifications from the South African Revenue Service (SARS) to breach company systems.<\/p>\n\n\n\n<p>The group employed multiple email addresses and other methods in sophisticated attacks targeting local companies. Clicking links or downloading attachments could see systems completely taken over.<\/p>\n\n\n\n<p>&#8220;The phishing emails were crafted to appear as official tax audit notifications or to prompt recipients to download an archive purportedly containing a &#8216;list of tax violations,'&#8221; said security group Kaspersky.\u00a0<\/p>\n\n\n\n<p>SilverFox aimed to exploit the perceived authority and urgency of communications from tax agencies across South Africa, India, Indonesia and Russia to breach companies across multiple sectors.<\/p>\n\n\n\n<p>This included industrial, consulting, trade and transportation sectors between January and February 2026, with more than 1,600 malicious emails recorded by researchers at Kaspersky.<\/p>\n\n\n\n<p>The main attack vector was a social engineering technique that persuaded recipients of the email to download a file, triggering the attack chain.<\/p>\n\n\n\n<p>In one example of a <a href=\"https:\/\/www.sars.gov.za\/wp-content\/uploads\/Docs\/Scams\/SARS-SCAM-390-%E2%80%93-SARS-Summons-%E2%80%93-10-February-2026.pdf\">phishing email attempt collected by SARS<\/a> on 10 February 2026, the sender accused the recipient of failing to pay their outstanding tax debt for one or more years.<\/p>\n\n\n\n<p>Attached to the email is a fake court summons with a button labelled &#8220;view legal document &amp; case details here&#8221;, which downloads a 62.3KB file.<\/p>\n\n\n\n<p>&#8220;Social engineering played a key role in this campaign,&#8221; said Anton Kargin, senior security researcher at Kaspersky&#8217;s global research and analysis team.<\/p>\n\n\n\n<p>&#8220;At the same time, SilverFox employed a multi-stage delivery approach for the primary malicious payload and utilised multiple email addresses and domains.&#8221;<\/p>\n\n\n\n<p>Lionel Dartnall, country manager SADC for international cybersecurity firm Check Point Software, also described the sophisticated techniques employed by SilverFox to breach companies.<\/p>\n\n\n\n<p>&#8220;As part of the infection chain, the group employs a &#8216;bring your own vulnerable driver&#8217; technique to terminate security product processes and reduce the chances of detection,&#8221; he told MyBroadband.<\/p>\n\n\n\n<p>&#8220;Their techniques have become more sophisticated and more &#8216;APT-like&#8217; (advanced persistent threat), blending espionage tactics with financially motivated attacks.&#8221;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">SilverFox shifts attention to South Africa, India, Russia<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/Dartnall-Check-Point-1200x675.jpg\" alt=\"\" class=\"wp-image-646159\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/Dartnall-Check-Point-1200x675.jpg 1200w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/Dartnall-Check-Point-600x338.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/Dartnall-Check-Point-768x432.jpg 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/Dartnall-Check-Point-1536x864.jpg 1536w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/05\/Dartnall-Check-Point.jpg 1600w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><figcaption class=\"wp-element-caption\">Lionel Dartnall, country manager SADC for Check Point Software<\/figcaption><\/figure>\n\n\n\n<p>During this campaign, SilverFox added a new Python-based backdoor called &#8220;ABCDoor.&#8221; This was an updated version of a backdoor called ValleyRat, which the group used extensively in Asia.<\/p>\n\n\n\n<p>Specifically, it used this backdoor to target organisations in Taiwan and Japan. ABCDoor allowed the group to terminate security product processes and reduce the chances of detection.<\/p>\n\n\n\n<p>The group was previously focused solely on the East Asian market, targeting enterprises in the telecommunications, energy, logistics, and finance sectors.<\/p>\n\n\n\n<p>&#8220;Check Point has since seen many attacks instigated by this group globally, which deploys several social engineering, fake software, and stealthy malware delivery methods to breach organisations,&#8221; said Dartnall.<\/p>\n\n\n\n<p>Kaspersky said that the backdoor, delivered through the downloaded file, allowed the threat actor to remotely control infected systems and upload and download files at will.<\/p>\n\n\n\n<p>&#8220;In addition, a modified and previously undocumented version of RustSL was used to deliver ValleyRAT, first deployed by the threat actor in late December 2025,&#8221; it said.<\/p>\n\n\n\n<p>SilverFox used a wide-ranging email campaign across multiple email addresses to minimise the likelihood of detection and disruption.<\/p>\n\n\n\n<p>Dartnall recommended that companies in South Africa implement IOC (Indicator of Compromise) blocking and IPS (Intrusion Prevention System) enforcement.<\/p>\n\n\n\n<p>Additionally, practices such as accelerated patching, updating, and running hotfixes should be prioritised, as well as the enforcement of multifactor authentication for employees.<\/p>\n\n\n\n<p>Meanwhile, Kaspersky said that these attack chains can be stopped by regularly improving employees&#8217; digital literacy and increasing phishing awareness.<\/p>\n\n\n\n<p>Alternatively, using a solution that automatically blocks suspicious emails and scans password-protected archives could prevent threat actors like SilverFox from gaining access to company systems.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hacker group SilverFox spent January and February attempting to hack South African companies using fake SARS tax emails.<\/p>\n","protected":false},"author":341213,"featured_media":646154,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[105083,104783,15227,1595,105084,417,509,105082,4336,105086],"class_list":["post-646153","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-anton-kargin","tag-check-point-software","tag-cybersecurity","tag-kaspersky","tag-lionel-dartnall","tag-phishing","tag-sars","tag-silverfox","tag-south-african-revenue-service","tag-valleyrat"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/646153"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341213"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=646153"}],"version-history":[{"count":3,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/646153\/revisions"}],"predecessor-version":[{"id":646193,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/646153\/revisions\/646193"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/646154"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=646153"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=646153"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=646153"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}