SEPTEMBER 30, 2025

SilverFox has quickly emerged in 2024 and 2025 as a competent and adaptable threat actor operating on the nexus of espionage and financially motivated operations. Its ability to take an opportunistic targeting approach while employing advanced intrusion techniques positions the group among threat actors that defenders cannot afford to ignore. Recent intelligence confirms SilverFox has moved away from opportunistic targeting with smaller breaches and instead focused on prolonged operations against organizations that represent enhanced operational value in the government, finance, and technology sectors.
Attribution: SilverFox is assessed with moderate confidence to be state-aligned and there have been indications of a degree of coordination across Eastern Europe and Central Asia.
Active Since: There was public reporting on activity from as early as 2022, but there are indications the group has significantly increased its operational tempo since late 2023.
Aliases: While confirmed overlaps with other units are limited, their activity does sometimes overlap with the infrastructure established by Qilin affiliates.
Motivation: SilverFox uses a combination of strategic espionage targeting of government and telecommunications organizations, along with financially motivated operations such as ransomware and data extortion.
SilverFox utilized a hybrid operational style:
Techniques:
Supply chain targeting of European software vendors.
Lateral movement through hybridized cloud and on-prem networks.
Data exfiltration occurred prior to encryption with ransomware only used selectively.
SilverFox has demonstrated rapid evolution:
SilverFox is a powerful example of the merger of espionage and financial cybercrime in 2025. The dual-motives, targeting the supply chain, and rapid advances on use of AI as disruptive assets make them an unpredictable and dangerously active actor.
Defensive Takeaways:
SilverFox is continuing to emerge on the global threat landscape requiring co-ordinated international monitoring and cyber defense planning.
You can download and review the sheet for all the details!

Take control of your digital security with an exclusive demo of our powerful threat management platform.