logo

Silver Fox Uses Fake Tax Notices to Deploy ValleyRAT and New ABCDoor Backdoor

ID: a0853875-e298-5ff8-9bd6-358c0877977b

STIX ID: report--a0853875-e298-5ff8-9bd6-358c0877977b

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

Silver Fox, a Chinese-linked threat group, ran large-scale phishing campaigns impersonating tax authorities (notably targeting India and Russia) that delivered a custom RustSL loader which unpacks ValleyRAT and a newly documented Cython-compiled Python backdoor named ABCDoor; the report describes the multi-stage infection chain, geofencing and steganography in the loader, persistence (registry Run key, scheduled task “AppClient”, Phantom Persistence), use of ffmpeg and pythonw.exe for stealthy data collection, and IoCs such as C2 third-level “abc” subdomains and C:\ProgramData\Tailscale paths, and offers detection and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.