logo

Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia

ID: d9f1af6f-2f7d-5e17-82e9-06f37432b2ac

STIX ID: report--d9f1af6f-2f7d-5e17-82e9-06f37432b2ac

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-05-04

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Silver Fox (aka Monarch/SwimSnake) ran phishing campaigns in Dec 2025–Jan 2026 targeting organizations in India, Russia and other countries, delivering a modified RustSL loader that unpacks an encrypted ValleyRAT payload and a newly observed Python backdoor dubbed ABCDoor; the report documents infection chains (tax-themed lures, PDF/ZIP/RAR/SFX delivery), persistence and evasion techniques (geofencing, VM/sandbox checks, Phantom Persistence), observed sectors and scale (1,600+ phishing emails flagged), and evolving delivery methods and targets since 2024.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.