BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Silver Fox Cyberattacks Target India, Russia With ABCDoor

Silver Fox deploys tax-themed phishing, ABCDoor backdoor, and novel persistence against global targets.

  • The China-based Silver Fox group is targeting organizations in Russia and India with a new Python backdoor called ABCDoor.
  • The campaign uses phishing emails disguised as official tax notices to deliver a modified Rust-based loader called RustSL, which installs the ValleyRAT backdoor.
  • The malware implements sophisticated geofencing and persistence techniques, including a novel method called Phantom Persistence, to avoid detection.
  • More than 1,600 phishing emails were sent between January and February 2026, impacting industrial, consulting, retail, and transportation sectors.
  • The threat actor has evolved from targeting China to a broader operational scope, now including Taiwan and Japan.

In early 2026, the cybercrime group Silver Fox launched a sophisticated malware campaign targeting entities in Russia and India, according to reports from Kaspersky. The attack delivered a previously undocumented backdoor codenamed ABCDoor via phishing emails impersonating tax authorities.

- Advertisement -

These emails mimicked official notices from the Income Tax Department of India regarding audits. Consequently, victims were tricked into downloading archives containing a malicious executable disguised as a PDF file.

The executable was a modified version of an open-source shellcode loader called RustSL, first used by the group in late December 2025. This loader performed environment checks to evade virtual machines and implemented geofencing for specific countries.

Its ultimate purpose was to unpack and install the well-known ValleyRAT backdoor. One loader variant even employed a novel persistence technique, “intercept[ing] the system shutdown signal, halt[ing] the normal shutdown sequence, and trigger[ing] a reboot under the guise of an update for the malware.”

The encrypted payload then downloaded the ABCDoor backdoor, which had been in the actor’s arsenal since at least December 2024. This Python-based tool allowed for remote control, data collection, and file exfiltration from compromised systems.

- Advertisement -

Meanwhile, the campaign’s geographic focus has expanded over time. While earlier RustSL versions only listed China, the custom variant used in these attacks included India, Indonesia, South Africa, Russia, and Cambodia.

As recently as November 2025, Silver Fox used a JavaScript loader to deliver ABCDoor. Newer RustSL loaders have since added Japan to their target list, with the highest number of attacks detected in India, Russia, and Indonesia.

The group has adopted a dual-track model for both profit and espionage. Security firm S2W noted the group “primarily utilizes highly customized spear phishing techniques for initial infiltration, deploying sophisticated and diversified attack scenarios tailored to the seasonal issues of the target country.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Mining Mogul Chun Wang Purchases SpaceX Mars Mission

Chun Wang, founder of the Bitcoin mining pool F2Pool, has purchased and will join...

TrapDoor Malware Targets npm, PyPI, Crates.io in Supply Chain Attack

A coordinated supply chain attack, codenamed TrapDoor, has deployed malware across three major developer...

$1,000 in SHIB Could’ve Become $99.1 Million

A $1,000 investment in Shiba Inu on its all-time low day in November 2020...

BitMEX Analyst: Bond Yield Surge Fuels Bitcoin Supercycle

A Bitmex analyst argues surging sovereign bond yields will force a "structural" shift, creating...

U.S. Lawmakers Push “Fort Knox” Bitcoin Reserve Plan

The ARMA Act proposes creating a U.S. Strategic Bitcoin Reserve, backed by 5% of...

Must Read

What Is Bcrypt Password Hashing Function?

KEY TAKEAWAYSBcrypt is a password hashing function that transforms plain passwords into unique alphanumeric sequences.It is a one-way process, ensuring that passwords cannot be...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading