Silver Fox Uses Fake Tax Notices to Deploy ValleyRAT and New ABCDoor Backdoor
ID: a0853875-e298-5ff8-9bd6-358c0877977b
STIX ID: report--a0853875-e298-5ff8-9bd6-358c0877977b
Feed Name: cybersecurityNews.com
Silver Fox, a Chinese-linked threat group, ran large-scale phishing campaigns impersonating tax authorities (notably targeting India and Russia) that delivered a custom RustSL loader which unpacks ValleyRAT and a newly documented Cython-compiled Python backdoor named ABCDoor; the report describes the multi-stage infection chain, geofencing and steganography in the loader, persistence (registry Run key, scheduled task “AppClient”, Phantom Persistence), use of ffmpeg and pythonw.exe for stealthy data collection, and IoCs such as C2 third-level “abc” subdomains and C:\ProgramData\Tailscale paths, and offers detection and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
