BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Silver Fox Cyberattacks Target India, Russia With ABCDoor

Silver Fox deploys tax-themed phishing, ABCDoor backdoor, and novel persistence against global targets.

  • The China-based Silver Fox group is targeting organizations in Russia and India with a new Python backdoor called ABCDoor.
  • The campaign uses phishing emails disguised as official tax notices to deliver a modified Rust-based loader called RustSL, which installs the ValleyRAT backdoor.
  • The malware implements sophisticated geofencing and persistence techniques, including a novel method called Phantom Persistence, to avoid detection.
  • More than 1,600 phishing emails were sent between January and February 2026, impacting industrial, consulting, retail, and transportation sectors.
  • The threat actor has evolved from targeting China to a broader operational scope, now including Taiwan and Japan.

In early 2026, the cybercrime group Silver Fox launched a sophisticated malware campaign targeting entities in Russia and India, according to reports from Kaspersky. The attack delivered a previously undocumented backdoor codenamed ABCDoor via phishing emails impersonating tax authorities.

- Advertisement -

These emails mimicked official notices from the Income Tax Department of India regarding audits. Consequently, victims were tricked into downloading archives containing a malicious executable disguised as a PDF file.

The executable was a modified version of an open-source shellcode loader called RustSL, first used by the group in late December 2025. This loader performed environment checks to evade virtual machines and implemented geofencing for specific countries.

Its ultimate purpose was to unpack and install the well-known ValleyRAT backdoor. One loader variant even employed a novel persistence technique, “intercept[ing] the system shutdown signal, halt[ing] the normal shutdown sequence, and trigger[ing] a reboot under the guise of an update for the malware.”

The encrypted payload then downloaded the ABCDoor backdoor, which had been in the actor’s arsenal since at least December 2024. This Python-based tool allowed for remote control, data collection, and file exfiltration from compromised systems.

- Advertisement -

Meanwhile, the campaign’s geographic focus has expanded over time. While earlier RustSL versions only listed China, the custom variant used in these attacks included India, Indonesia, South Africa, Russia, and Cambodia.

As recently as November 2025, Silver Fox used a JavaScript loader to deliver ABCDoor. Newer RustSL loaders have since added Japan to their target list, with the highest number of attacks detected in India, Russia, and Indonesia.

The group has adopted a dual-track model for both profit and espionage. Security firm S2W noted the group “primarily utilizes highly customized spear phishing techniques for initial infiltration, deploying sophisticated and diversified attack scenarios tailored to the seasonal issues of the target country.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin Weakness May Force Treasury Firm Consolidations

Strategy (MSTR) purchased 1,587 Bitcoin for $100 million last week, marking its second consecutive...

Crypto’s Tokenized Stocks Fail Again

Crypto exchanges canceled tokenized SpaceX IPO allocations, leaving users with over $1 billion in...

MicroStrategy Buys $100M BTC Below Average Cost

Strategy purchased 1,587 BTC for $100 million last week at an average price of...

Malicious Chrome Wallpaper Extensions Infect 105K Users

A cluster of 152 Google Chrome extensions has been discovered distributing a potentially unwanted...

Citi And Bank Of America Boost AMD Price Targets

Citi upgraded AMD from "neutral" to "buy" and raised its price target from $460...

Must Read

Top Best Metaverse Worlds To Buy Land

The metaverse has grown in our everyday conversation since Facebook announced its rebranding in October 2021 to META. The metaverse is a virtual world,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading