Silver Fox Uses Fake Tax Notices to Drop ValleyRAT and ABCDoor Backdoor
ID: f52f8036-21b8-54f8-9870-5f2c32d62736
STIX ID: report--f52f8036-21b8-54f8-9870-5f2c32d62736
Feed Name: GBHackers
Silver Fox conducted tax‑themed phishing waves in late 2025–early 2026 that delivered a forked RustSL loader embedding encrypted payloads (ValleyRAT and a Python backdoor called ABCDoor). The campaign used direct attachments and PDF links, employed steganography, geofencing to restrict execution to targeted countries, and advanced persistence (Phantom Persistence), enabling remote screen broadcasting, input emulation, and modular plugin delivery across India, Russia, Indonesia and other targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
