BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Silver Fox Cyberattacks Target India, Russia With ABCDoor

Silver Fox deploys tax-themed phishing, ABCDoor backdoor, and novel persistence against global targets.

  • The China-based Silver Fox group is targeting organizations in Russia and India with a new Python backdoor called ABCDoor.
  • The campaign uses phishing emails disguised as official tax notices to deliver a modified Rust-based loader called RustSL, which installs the ValleyRAT backdoor.
  • The malware implements sophisticated geofencing and persistence techniques, including a novel method called Phantom Persistence, to avoid detection.
  • More than 1,600 phishing emails were sent between January and February 2026, impacting industrial, consulting, retail, and transportation sectors.
  • The threat actor has evolved from targeting China to a broader operational scope, now including Taiwan and Japan.

In early 2026, the cybercrime group Silver Fox launched a sophisticated malware campaign targeting entities in Russia and India, according to reports from Kaspersky. The attack delivered a previously undocumented backdoor codenamed ABCDoor via phishing emails impersonating tax authorities.

- Advertisement -

These emails mimicked official notices from the Income Tax Department of India regarding audits. Consequently, victims were tricked into downloading archives containing a malicious executable disguised as a PDF file.

The executable was a modified version of an open-source shellcode loader called RustSL, first used by the group in late December 2025. This loader performed environment checks to evade virtual machines and implemented geofencing for specific countries.

Its ultimate purpose was to unpack and install the well-known ValleyRAT backdoor. One loader variant even employed a novel persistence technique, “intercept[ing] the system shutdown signal, halt[ing] the normal shutdown sequence, and trigger[ing] a reboot under the guise of an update for the malware.”

The encrypted payload then downloaded the ABCDoor backdoor, which had been in the actor’s arsenal since at least December 2024. This Python-based tool allowed for remote control, data collection, and file exfiltration from compromised systems.

- Advertisement -

Meanwhile, the campaign’s geographic focus has expanded over time. While earlier RustSL versions only listed China, the custom variant used in these attacks included India, Indonesia, South Africa, Russia, and Cambodia.

As recently as November 2025, Silver Fox used a JavaScript loader to deliver ABCDoor. Newer RustSL loaders have since added Japan to their target list, with the highest number of attacks detected in India, Russia, and Indonesia.

The group has adopted a dual-track model for both profit and espionage. Security firm S2W noted the group “primarily utilizes highly customized spear phishing techniques for initial infiltration, deploying sophisticated and diversified attack scenarios tailored to the seasonal issues of the target country.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

MSFT May 2026 Outlook: Stagnation at $413 Predicted

Microsoft stock (NASDAQ: MSFT) opened Monday at $414 after surging more than 11% in...

Stablecoin Yield Rules Compromised in Clarity Act

A bipartisan deal on a key clause of the stablecoin bill was reached, led...

US Law Firm Blocks Ether Return in Kelp Hack

A US law firm has secured a court order blocking the transfer of $73...

Bitcoin Reclaims $80,000 for First Time Since Early 2026

Bitcoin (BTC) has reclaimed the $80,000 price level for the first time since late...

‘Stablecoin’ term outdated as sector hits $321B

The term "stablecoin" is now outdated as the technology's primary focus has shifted from...

Must Read

The Ultimate Guide on How to Understand a Cryptocurrency White Paper

Today, cryptocurrency is a popular buzzword. We hear about it on the news, we read about it on the Internet. Yet, people are reluctant to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading