Silver Fox Campaign Deploys ValleyRAT Through Tax-Themed Lures
ID: 88f5f2ce-0fab-5508-a203-408201276d0e
STIX ID: report--88f5f2ce-0fab-5508-a203-408201276d0e
Feed Name: Cyber Press
Between late 2025 and early 2026 the Silver Fox APT ran a multi-stage, tax-themed phishing campaign against organizations in India and Russia that used a custom Rust loader (RustSL) to load ValleyRAT and a newly identified ABCDoor backdoor (which streams the victim's screen via ffmpeg and enables remote control and data theft). The report details delivery variations (RAR-embedded executables, PDFs with external links), registry persistence, auxiliary plugins delivering a Python environment and ABCDoor, and recommends enhancing endpoint detection, monitoring unusual Python activity, and strengthening phishing defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
