{"id":11680,"date":"2026-03-28T10:03:35","date_gmt":"2026-03-28T10:03:35","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/28\/new-silver-fox-campaign-hits-japanese-businesses-with-tax-themed-phishing-lures\/"},"modified":"2026-03-28T10:03:35","modified_gmt":"2026-03-28T10:03:35","slug":"new-silver-fox-campaign-hits-japanese-businesses-with-tax-themed-phishing-lures","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/28\/new-silver-fox-campaign-hits-japanese-businesses-with-tax-themed-phishing-lures\/","title":{"rendered":"New Silver Fox Campaign Hits Japanese Businesses With Tax-Themed Phishing Lures"},"content":{"rendered":"<p>    New Silver Fox Campaign Hits Japanese Businesses With Tax-Themed Phishing Lures<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Japan\u2019s tax season has become a hunting ground for a well-organized threat actor known as Silver Fox. <\/p>\n<p>As Japanese companies enter their annual cycle of tax filing, salary reviews, and personnel changes, this group is taking full advantage of the moment \u2014 sending highly targeted spearphishing emails designed to look like routine internal communications. <\/p>\n<p>The campaign currently targets manufacturers and various other businesses across Japan, exploiting a time when employees are naturally expecting emails about financial and HR matters.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/134708c8-f772-486a-a1fe-125908e7d8f9\/New-Silver-Fox-Campaign-Hits-Japanese-Businesses-With-Tax-Themed-Phishing-Lures.pdf?AWSAccessKeyId=ASIA2F3EMEYERJOUSAU3&amp;Signature=E%2BJgsTs7UsdR1XK5eebxngrNiVs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEBMaCXVzLWVhc3QtMSJHMEUCIF%2BpFIfuSaGiTkt1HO2eKKJrhVA%2FZoHuFNL1bVKwGvZkAiEAjxgkEIJ1KO%2BjvgKKySBAtlQUgxCbeoLHlRL%2Fmjrxcnwq%2FAQI3P%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDDHc%2FYn%2Bz39mFLIhYirQBOAoHn27WBVo3DOkbOn2TSdlyf7s6KDkE7KoHG89iXmlWJjtJe5mvdpwRcNdOT8RLSdUMY9MbK%2Fq3afllextg9V0DAtNsNo6cUp4vLat6L2T%2B2hyhG3JcPvsOM6Jo5TZNiigkQ2XW9Gg1d1fwskW54C%2FYo2xqjQqPdJgjF5tkUuDTcSbJmKmy1wLVKGRrmkjV8ORQLQWDDAJAiElpUv1QBk8t3PNJTAFLlmwwa%2BifKIyuq6Q6Zy6oSLwQ5QeEDjhyxNVqwZu3JSgMbNoBHrpFphSzW07cKBzekqz1cQNEsopy2WvM%2BCrtaSJU2yRIBdI%2FM2Ik8DXMIML6TIrop%2BfLMMMz3Un3QJyLDGarMLj%2BU04v77W%2FAqVk%2FLbm4a%2FoBRTxTfBnQnNu5isCoRDvec3OuecdoULYc%2F2alLYKRUlCrLKutF95f1Nd%2BworXLLHAHq%2BgUVrgRDWa8F%2Fyb%2FQgLXpKQiYE1xw7exo4l6KFACoby8qjlSG1pVpUlLdamHnQJe7r%2F9E%2BzN11D4LCo67lq2zK8lOyakpo%2FDOjsO8HTAxr7nOyxfONww0pbPUjDKCwIZwz8ojS88JVHO9rH%2BsVaFq37bddgXSdQJxf7BReSrpPIce0lTGIHc8svfw3fjSBIEx1JpmQZHAuJPD3gQyRM93YcBK9pS%2FayqmiLzFbBzO3Mxw0oiqMJ9zSleOOANlMdMlz07LuIGYEp0nXDN21p6XGEX0sM22bmNuv6W42mdHTnlQ2to7wBawwJ2kLhd%2F9USqrapBj0KZZj%2BfL3rW%2FQUmBow0MaZzgY6mAEJw3c2ZkM43eEnr5gW%2Fo%2BXMRMAIVfM%2FUNWiqmthyIIGrD5xIjoby0syB%2FT5eVegu6QmuMMI7YcO4h%2BoOgMcugcT7ae8go0T0HEPU%2FI3YqwDFERu7Vo9TcGMwitZ5VXedR7NVLon7tDG1W36n%2BhkU0%2FjgTkjWbOJM0BCd%2F11k%2BBdDaW%2FZpkg51JxuJmIGa%2BlMgzctnpsSYW6g%3D%3D&amp;Expires=1774610131\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Silver Fox has been active since at least 2023. The group initially focused on Chinese-speaking targets before expanding operations into Southeast Asia, Japan, and potentially North America, running each campaign in the local language. <\/p>\n<p>Over the years, the group has targeted a wide range of industries \u2014 finance, healthcare, education, gaming, government, and even cybersecurity. <\/p>\n<p>This broad reach shows that Silver Fox is not a one-trick operation; it adapts its tactics to fit the environment and the season. <\/p>\n<p>This latest campaign against Japan is a continuation of a pattern observed during the same period last year, confirming that the group deliberately times its attacks around predictable business cycles.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/134708c8-f772-486a-a1fe-125908e7d8f9\/New-Silver-Fox-Campaign-Hits-Japanese-Businesses-With-Tax-Themed-Phishing-Lures.pdf?AWSAccessKeyId=ASIA2F3EMEYERJOUSAU3&amp;Signature=E%2BJgsTs7UsdR1XK5eebxngrNiVs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEBMaCXVzLWVhc3QtMSJHMEUCIF%2BpFIfuSaGiTkt1HO2eKKJrhVA%2FZoHuFNL1bVKwGvZkAiEAjxgkEIJ1KO%2BjvgKKySBAtlQUgxCbeoLHlRL%2Fmjrxcnwq%2FAQI3P%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDDHc%2FYn%2Bz39mFLIhYirQBOAoHn27WBVo3DOkbOn2TSdlyf7s6KDkE7KoHG89iXmlWJjtJe5mvdpwRcNdOT8RLSdUMY9MbK%2Fq3afllextg9V0DAtNsNo6cUp4vLat6L2T%2B2hyhG3JcPvsOM6Jo5TZNiigkQ2XW9Gg1d1fwskW54C%2FYo2xqjQqPdJgjF5tkUuDTcSbJmKmy1wLVKGRrmkjV8ORQLQWDDAJAiElpUv1QBk8t3PNJTAFLlmwwa%2BifKIyuq6Q6Zy6oSLwQ5QeEDjhyxNVqwZu3JSgMbNoBHrpFphSzW07cKBzekqz1cQNEsopy2WvM%2BCrtaSJU2yRIBdI%2FM2Ik8DXMIML6TIrop%2BfLMMMz3Un3QJyLDGarMLj%2BU04v77W%2FAqVk%2FLbm4a%2FoBRTxTfBnQnNu5isCoRDvec3OuecdoULYc%2F2alLYKRUlCrLKutF95f1Nd%2BworXLLHAHq%2BgUVrgRDWa8F%2Fyb%2FQgLXpKQiYE1xw7exo4l6KFACoby8qjlSG1pVpUlLdamHnQJe7r%2F9E%2BzN11D4LCo67lq2zK8lOyakpo%2FDOjsO8HTAxr7nOyxfONww0pbPUjDKCwIZwz8ojS88JVHO9rH%2BsVaFq37bddgXSdQJxf7BReSrpPIce0lTGIHc8svfw3fjSBIEx1JpmQZHAuJPD3gQyRM93YcBK9pS%2FayqmiLzFbBzO3Mxw0oiqMJ9zSleOOANlMdMlz07LuIGYEp0nXDN21p6XGEX0sM22bmNuv6W42mdHTnlQ2to7wBawwJ2kLhd%2F9USqrapBj0KZZj%2BfL3rW%2FQUmBow0MaZzgY6mAEJw3c2ZkM43eEnr5gW%2Fo%2BXMRMAIVfM%2FUNWiqmthyIIGrD5xIjoby0syB%2FT5eVegu6QmuMMI7YcO4h%2BoOgMcugcT7ae8go0T0HEPU%2FI3YqwDFERu7Vo9TcGMwitZ5VXedR7NVLon7tDG1W36n%2BhkU0%2FjgTkjWbOJM0BCd%2F11k%2BBdDaW%2FZpkg51JxuJmIGa%2BlMgzctnpsSYW6g%3D%3D&amp;Expires=1774610131\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p><a href=\"https:\/\/www.welivesecurity.com\/en\/business-security\/cunning-predator-how-silver-fox-preys-japanese-firms-tax-season\/\" id=\"https:\/\/www.welivesecurity.com\/en\/business-security\/cunning-predator-how-silver-fox-preys-japanese-firms-tax-season\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">WeLiveSecurity analysts identified this ongoing campaign<\/a> and noted that Silver Fox\u2019s emails are not generic blasts. The attackers conduct prior reconnaissance on each target, gathering real employee names and even CEO identities to use as spoofed senders. <\/p>\n<p>Each email includes the target company\u2019s name directly in the subject line, making the message feel like a legitimate internal notification. <\/p>\n<p>Subject lines reference topics such as tax compliance violations, salary adjustments, employee stock ownership plan changes, and personnel updates \u2014 exactly the kind of messages employees expect and trust during this busy season. <\/p>\n<p>This level of pre-attack research is what separates Silver Fox from lower-tier threat actors and makes its campaigns significantly harder to spot.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjVgFHHP_cankfTdah6Srhq81xUd2IUmsSxapdjodlyk50XBiW31VbSieqvngcqqWt4AVfGf5HtLflSHTlCTCjzGhy24PNir8S5OfCQzMVbjJHSLGgMQKtB6HqPUFcEuBjZl_jChnH3evdSNfC5ferjHrLDEcqM__QxZPTDmhKGSaj13SvvuFS2XwlEkE8\/s16000\/Spearphishing%2520email%2520distributed%2520on%25202026-03-11%2520%28Source%2520-%2520Welivesecurity%29.webp?ssl=1\" alt=\"Spearphishing email distributed on 2026-03-11 (Source - Welivesecurity)\"><figcaption class=\"wp-element-caption\">Spearphishing email distributed on 2026-03-11 (Source \u2013 Welivesecurity)<\/figcaption><\/figure>\n<p>The emails carry either malicious attachments or links that lead to pages where victims are instructed to download a file. <\/p>\n<p>These shows the examples of <a href=\"https:\/\/cybersecuritynews.com\/beware-of-phishing-emails-as-spam-filter\/\" id=\"133319\" target=\"_blank\" rel=\"noreferrer noopener\">spearphishing emails<\/a> distributed on March 11 and March 12, 2026, respectively, while a tax-related lure webpage used to push the malicious download. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhAktsikQ-6qaPyoLScFGQfy86-8s0eyy9PdypdXJkQ86PWQ8h7eOPklYTV20pcudgdnKjghFy0j8Ouzyjysp_4at2OQ7GRrYZoH5LNUGOr9Oc2LfUFKpmRnxGKHX7GSSWxxeIFR-Ij4TCvMoxCe1xtscsm-oY61JszA9DNu3RtCTO16HVpnOjjX9Gribw\/s16000\/Spearphishing%2520email%2520distributed%2520on%25202026-03-12%2520%28Source%2520-%2520Welivesecurity%29.webp?ssl=1\" alt=\"Spearphishing email distributed on 2026-03-12 (Source - Welivesecurity)\"><figcaption class=\"wp-element-caption\">Spearphishing email distributed on 2026-03-12 (Source \u2013 Welivesecurity)<\/figcaption><\/figure>\n<\/div>\n<p>Opening any of these files drops ValleyRAT onto the victim\u2019s machine \u2014 a remote access trojan that ESET products detect as Win64\/Valley. Once installed, ValleyRAT gives the attacker full remote control of the compromised system. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgRBSj-dyglCcFiwb9EHEKuORBm5Mmm5_6bqRqqfxjEx6UZ2M2rKes1Rp3RWMgKcK_TI92-yGtqhRTVKdhuSacmT3CQXYa1Ft7hfXh0H78_-RK9M60do9zUw77gqJp5vFKQ5xZ6RX1pP7tD0hYAYmFT4EOw3Z418WUZTlWFMetF1dSvE4mpxrugo5elN24\/s16000\/Tax-related%2520lure%2520webpage%2520instructing%2520the%2520target%2520to%2520download%2520a%2520malicious%2520file%2520%28Source%2520-%2520Welivesecurity%29.webp?ssl=1\" alt=\"Tax-related lure webpage instructing the target to download a malicious file (Source - Welivesecurity)\"><figcaption class=\"wp-element-caption\">Tax-related lure webpage instructing the target to download a malicious file (Source \u2013 Welivesecurity)<\/figcaption><\/figure>\n<\/div>\n<p>This allows them to steal <a href=\"https:\/\/cybersecuritynews.com\/openclaw-ai-agents-leak-sensitive-data\/\" id=\"144974\" target=\"_blank\" rel=\"noreferrer noopener\">sensitive data<\/a>, monitor user activity, and move deeper into the network to set up further stages of the attack.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/134708c8-f772-486a-a1fe-125908e7d8f9\/New-Silver-Fox-Campaign-Hits-Japanese-Businesses-With-Tax-Themed-Phishing-Lures.pdf?AWSAccessKeyId=ASIA2F3EMEYERJOUSAU3&amp;Signature=E%2BJgsTs7UsdR1XK5eebxngrNiVs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEBMaCXVzLWVhc3QtMSJHMEUCIF%2BpFIfuSaGiTkt1HO2eKKJrhVA%2FZoHuFNL1bVKwGvZkAiEAjxgkEIJ1KO%2BjvgKKySBAtlQUgxCbeoLHlRL%2Fmjrxcnwq%2FAQI3P%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDDHc%2FYn%2Bz39mFLIhYirQBOAoHn27WBVo3DOkbOn2TSdlyf7s6KDkE7KoHG89iXmlWJjtJe5mvdpwRcNdOT8RLSdUMY9MbK%2Fq3afllextg9V0DAtNsNo6cUp4vLat6L2T%2B2hyhG3JcPvsOM6Jo5TZNiigkQ2XW9Gg1d1fwskW54C%2FYo2xqjQqPdJgjF5tkUuDTcSbJmKmy1wLVKGRrmkjV8ORQLQWDDAJAiElpUv1QBk8t3PNJTAFLlmwwa%2BifKIyuq6Q6Zy6oSLwQ5QeEDjhyxNVqwZu3JSgMbNoBHrpFphSzW07cKBzekqz1cQNEsopy2WvM%2BCrtaSJU2yRIBdI%2FM2Ik8DXMIML6TIrop%2BfLMMMz3Un3QJyLDGarMLj%2BU04v77W%2FAqVk%2FLbm4a%2FoBRTxTfBnQnNu5isCoRDvec3OuecdoULYc%2F2alLYKRUlCrLKutF95f1Nd%2BworXLLHAHq%2BgUVrgRDWa8F%2Fyb%2FQgLXpKQiYE1xw7exo4l6KFACoby8qjlSG1pVpUlLdamHnQJe7r%2F9E%2BzN11D4LCo67lq2zK8lOyakpo%2FDOjsO8HTAxr7nOyxfONww0pbPUjDKCwIZwz8ojS88JVHO9rH%2BsVaFq37bddgXSdQJxf7BReSrpPIce0lTGIHc8svfw3fjSBIEx1JpmQZHAuJPD3gQyRM93YcBK9pS%2FayqmiLzFbBzO3Mxw0oiqMJ9zSleOOANlMdMlz07LuIGYEp0nXDN21p6XGEX0sM22bmNuv6W42mdHTnlQ2to7wBawwJ2kLhd%2F9USqrapBj0KZZj%2BfL3rW%2FQUmBow0MaZzgY6mAEJw3c2ZkM43eEnr5gW%2Fo%2BXMRMAIVfM%2FUNWiqmthyIIGrD5xIjoby0syB%2FT5eVegu6QmuMMI7YcO4h%2BoOgMcugcT7ae8go0T0HEPU%2FI3YqwDFERu7Vo9TcGMwitZ5VXedR7NVLon7tDG1W36n%2BhkU0%2FjgTkjWbOJM0BCd%2F11k%2BBdDaW%2FZpkg51JxuJmIGa%2BlMgzctnpsSYW6g%3D%3D&amp;Expires=1774610131\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 class=\"wp-block-heading\" id=\"how-the-attack-is-structured\"><strong>How the Attack Is Structured<\/strong><\/h2>\n<p>The infection chain behind this particular campaign is straightforward but effective. After a victim opens the malicious file \u2014 typically disguised as a salary notice or HR document \u2014 ValleyRAT silently takes hold of the system. <\/p>\n<p>The trojan then maintains persistence in the environment, meaning it continues running even after restarts, keeping the attacker\u2019s access alive over time. <\/p>\n<p>The files are often delivered through publicly available file-hosting services such as gofile[.]io or WeTransfer, which adds another layer of deception since these are recognizable platforms. <\/p>\n<p>Archives in RAR or ZIP format are commonly used to package the payload, making it less immediately obvious to the recipient.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/134708c8-f772-486a-a1fe-125908e7d8f9\/New-Silver-Fox-Campaign-Hits-Japanese-Businesses-With-Tax-Themed-Phishing-Lures.pdf?AWSAccessKeyId=ASIA2F3EMEYERJOUSAU3&amp;Signature=E%2BJgsTs7UsdR1XK5eebxngrNiVs%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEBMaCXVzLWVhc3QtMSJHMEUCIF%2BpFIfuSaGiTkt1HO2eKKJrhVA%2FZoHuFNL1bVKwGvZkAiEAjxgkEIJ1KO%2BjvgKKySBAtlQUgxCbeoLHlRL%2Fmjrxcnwq%2FAQI3P%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDDHc%2FYn%2Bz39mFLIhYirQBOAoHn27WBVo3DOkbOn2TSdlyf7s6KDkE7KoHG89iXmlWJjtJe5mvdpwRcNdOT8RLSdUMY9MbK%2Fq3afllextg9V0DAtNsNo6cUp4vLat6L2T%2B2hyhG3JcPvsOM6Jo5TZNiigkQ2XW9Gg1d1fwskW54C%2FYo2xqjQqPdJgjF5tkUuDTcSbJmKmy1wLVKGRrmkjV8ORQLQWDDAJAiElpUv1QBk8t3PNJTAFLlmwwa%2BifKIyuq6Q6Zy6oSLwQ5QeEDjhyxNVqwZu3JSgMbNoBHrpFphSzW07cKBzekqz1cQNEsopy2WvM%2BCrtaSJU2yRIBdI%2FM2Ik8DXMIML6TIrop%2BfLMMMz3Un3QJyLDGarMLj%2BU04v77W%2FAqVk%2FLbm4a%2FoBRTxTfBnQnNu5isCoRDvec3OuecdoULYc%2F2alLYKRUlCrLKutF95f1Nd%2BworXLLHAHq%2BgUVrgRDWa8F%2Fyb%2FQgLXpKQiYE1xw7exo4l6KFACoby8qjlSG1pVpUlLdamHnQJe7r%2F9E%2BzN11D4LCo67lq2zK8lOyakpo%2FDOjsO8HTAxr7nOyxfONww0pbPUjDKCwIZwz8ojS88JVHO9rH%2BsVaFq37bddgXSdQJxf7BReSrpPIce0lTGIHc8svfw3fjSBIEx1JpmQZHAuJPD3gQyRM93YcBK9pS%2FayqmiLzFbBzO3Mxw0oiqMJ9zSleOOANlMdMlz07LuIGYEp0nXDN21p6XGEX0sM22bmNuv6W42mdHTnlQ2to7wBawwJ2kLhd%2F9USqrapBj0KZZj%2BfL3rW%2FQUmBow0MaZzgY6mAEJw3c2ZkM43eEnr5gW%2Fo%2BXMRMAIVfM%2FUNWiqmthyIIGrD5xIjoby0syB%2FT5eVegu6QmuMMI7YcO4h%2BoOgMcugcT7ae8go0T0HEPU%2FI3YqwDFERu7Vo9TcGMwitZ5VXedR7NVLon7tDG1W36n%2BhkU0%2FjgTkjWbOJM0BCd%2F11k%2BBdDaW%2FZpkg51JxuJmIGa%2BlMgzctnpsSYW6g%3D%3D&amp;Expires=1774610131\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>To reduce the risk of falling victim to this campaign, WeLiveSecurity researchers recommended that employees verify any email about salary changes, tax penalties, or personnel updates through a separate channel \u2014 such as a phone call or a direct message \u2014 before taking any action. <\/p>\n<p>Recipients should also check whether the sender\u2019s email address actually matches the name displayed, as mismatches are a common sign of spoofing. <\/p>\n<p>Employees should also be cautious if the language in the email feels unusually stiff or formal, since Silver Fox operators are not native Japanese speakers and subtle phrasing errors sometimes appear in the messages. <\/p>\n<p>Organizations are also advised to keep <a href=\"https:\/\/cybersecuritynews.com\/compliance-management-software\/\" id=\"14197\" target=\"_blank\" rel=\"noreferrer noopener\">security software<\/a> up to date and to promptly report any suspicious email to the IT or security team, even when the email appears routine at first glance.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-silver-fox-campaign-hits-japanese-businesses\/\">New Silver Fox Campaign Hits Japanese Businesses With Tax-Themed Phishing Lures<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-silver-fox-campaign-hits-japanese-businesses\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Silver Fox Campaign Hits Japanese Businesses With Tax-Themed Phishing Lures Japan\u2019s tax season has become a hunting ground for a well-organized threat actor known as Silver Fox. As Japanese companies enter their annual cycle of tax filing, salary reviews, and personnel changes, this group is taking full advantage of the moment \u2014 sending highly [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-11680","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11680"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11680"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11680\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11680"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11680"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11680"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}