Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Silver Fox Targets India and Russia with ABCDoor Malware

Silver Fox Targets India and Russia with ABCDoor Malware

Posted on May 4, 2026 By CWS

The cybercrime group known as Silver Fox, based in China, has launched a malicious campaign targeting organizations within India and Russia. This campaign involves the deployment of a new malware, ABCDoor, through tax-themed phishing emails. The emails, designed to appear as legitimate communications from the Income Tax Department of India, were first identified in December 2025, with similar attacks targeting Russian entities soon after.

Phishing Tactics and Malware Delivery

The campaign utilized phishing emails that mimic official tax notices, urging recipients to download an archive purported to contain a list of tax violations. According to cybersecurity firm Kaspersky, these archives concealed a modified Rust-based loader sourced from a public repository. This loader was programmed to download and execute the well-established ValleyRAT backdoor, impacting sectors such as industrial, consulting, retail, and transportation. Over 1,600 phishing emails were detected between early January and February.

Kaspersky highlighted the introduction of a new ValleyRAT plugin that acts as a loader for the previously undocumented Python-based backdoor named ABCDoor. This backdoor has reportedly been part of Silver Fox’s toolkit since December 2024, actively used in attacks from February or March 2025 onwards.

Technical Aspects of the Attack

The attack typically begins with a phishing email containing a PDF file. This file includes links leading to a ZIP or RAR archive hosted on “abc.haijing88[.]com.” In December 2025, the malicious code was embedded directly within the email attachments. The archive contained an executable disguised as a PDF file, employing a modified open-source shellcode loader and antivirus bypass framework known as RustSL.

The primary objective of the RustSL variant used by Silver Fox is to decrypt and deploy the malicious payload. It also conducts geofencing and environment checks to identify if operations are occurring within virtual machines or sandboxes. Unlike the GitHub variant, which lists only China, Silver Fox’s version includes India, Indonesia, South Africa, Russia, and Cambodia.

Persistence and Wider Impacts

A notable feature of the attack is the use of Phantom Persistence, a technique that allows the malware to survive system reboots. Documented first in June 2025, this method halts the normal shutdown process to reboot the system, masquerading as an update to execute the malware upon startup. The encrypted payload results in the download of ValleyRAT malware, which manages command-and-control communications and executes additional modules.

Silver Fox’s operations have evolved, now employing a dual-track model that targets both opportunistic and espionage activities. Initially focusing on China, the group has expanded to include Taiwan and Japan. Despite the sophistication of their phishing tactics, the highest number of attacks has been observed in India, Russia, and Indonesia.

In conclusion, the Silver Fox group continues to adapt its strategies, leveraging tax-themed lures and sophisticated phishing methods to infiltrate targeted organizations. Their evolving tactics underscore the importance of robust cybersecurity measures to protect against such advanced threats.

The Hacker News Tags:ABCDoor malware, Cybercrime, Cybersecurity, India, Phantom Persistence, phishing attack, Russia, RustSL, Silver Fox, ValleyRAT

Post navigation

Previous Post: DigiCert Enhances Security After Support Portal Hack
Next Post: April 2026 Sees 33 Major Cybersecurity M&A Deals

Related Posts

Malicious Packages Target ASP.NET and npm Developers Malicious Packages Target ASP.NET and npm Developers The Hacker News
Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware The Hacker News
Chinese Hackers Murky, Genesis, and Glacial Panda Escalate Cloud and Telecom Espionage Chinese Hackers Murky, Genesis, and Glacial Panda Escalate Cloud and Telecom Espionage The Hacker News
AI Security Lags Behind as Skills Fail to Evolve AI Security Lags Behind as Skills Fail to Evolve The Hacker News
North Korean Hackers Use New AkdoorTea Backdoor to Target Global Crypto Developers North Korean Hackers Use New AkdoorTea Backdoor to Target Global Crypto Developers The Hacker News
Facebook’s New AI Tool Asks to Upload Your Photos for Story Ideas, Sparking Privacy Concerns Facebook’s New AI Tool Asks to Upload Your Photos for Story Ideas, Sparking Privacy Concerns The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • MicroStealer Malware Targets Telecom and Education Sectors
  • AI-Driven Cyber Threats Escalate: Key Exploits Revealed
  • xlabs_v1 Botnet Exploits Android Devices to Attack Minecraft
  • Two Americans Jailed for ALPHV BlackCat Ransomware Attacks
  • April 2026 Sees 33 Major Cybersecurity M&A Deals

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • MicroStealer Malware Targets Telecom and Education Sectors
  • AI-Driven Cyber Threats Escalate: Key Exploits Revealed
  • xlabs_v1 Botnet Exploits Android Devices to Attack Minecraft
  • Two Americans Jailed for ALPHV BlackCat Ransomware Attacks
  • April 2026 Sees 33 Major Cybersecurity M&A Deals

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark