logo

Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and India

ID: f08ffda1-a0a1-5890-8474-7f58b00e0147

STIX ID: report--f08ffda1-a0a1-5890-8474-7f58b00e0147

Feed Name: Securelist by Kaspersky

Threat Score
80/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Anton Kargin, Vladimir Gursky, Victoria Vlasova, Anna Lazaricheva

...
...

In late 2025–early 2026 the Silver Fox group conducted tax-themed phishing campaigns against organizations across multiple countries and sectors, using a customized RustSL loader to deploy ValleyRAT and a newly documented Python backdoor called ABCDoor; the report details the multi-stage attack chain, payload formats and decryption, persistence methods (including Phantom Persistence and scheduled tasks/registry autoruns), distribution changes over time, victims by country, and provides comprehensive network and file IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.