logo

Silver Fox Uses Fake Tax Notices to Drop ValleyRAT and ABCDoor Backdoor

ID: f52f8036-21b8-54f8-9870-5f2c32d62736

STIX ID: report--f52f8036-21b8-54f8-9870-5f2c32d62736

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Mayura Kathir

...
...

Silver Fox conducted tax‑themed phishing waves in late 2025–early 2026 that delivered a forked RustSL loader embedding encrypted payloads (ValleyRAT and a Python backdoor called ABCDoor). The campaign used direct attachments and PDF links, employed steganography, geofencing to restrict execution to targeted countries, and advanced persistence (Phantom Persistence), enabling remote screen broadcasting, input emulation, and modular plugin delivery across India, Russia, Indonesia and other targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.