Главная OSINT Новости Signals
CYBER

Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and India

🕓 1 мин чтения

Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and India

In December 2025, we detected a wave of malicious emails designed to look like official correspondence from the Indian tax service. A few weeks later, in January 2026, a similar campaign began targeting Russian organizations. We have attributed this activity to the Silver Fox threat group. Both waves followed a nearly identical structure: phishing emails were styled as official notices regarding tax audits or prompted users to download an archive containing a “list of tax violations”. Inside the archive was a modified Rust-based loader pulled from a public repository. This loader would download and execute the well-known ValleyRAT backdoor. The campaign impacted organizations across the industrial, consulting, retail, and transportation sectors, with over 1600 malicious emails recorded between early January and early February. During our investigation, we also discovered that the attacke

Source: https://securelist.com/silver-fox-tax-notification-campaign/119575/

Telegram X LinkedIn
К новостям