HomeSecuritySilver Fox targets Russia and India with ABCDoor malware

Silver Fox targets Russia and India with ABCDoor malware

The Chinese group Silver Fox is making a comeback, with cybersecurity analysts documenting a new, highly campaign phishing targeting critical organizations in India, Russia and other Asian markets, leveraging a backdoor called ABCDoor. The new activity confirms the group’s continued upgrading of its offensive capabilities and highlights a worrying shift towards more sophisticated cyberespionage operations.

Silver Fox Russia India ABCDoor malware

Tax baits as a lever for initial penetration

The campaign relied on massive but highly targeted phishing emailsthat mimicked official tax notices. In India, the messages appeared to be from the Income Tax Department, while a similar tactic was used in Russia with misleading notifications of alleged tax audits or lists of violations.

See also: Silver Fox targets Indian users with ValleyRAT malware

The method's success is based on social engineering: attackers exploit the sense of urgency created by a tax issue, leading victims to download malicious attachments or compressed ZIP and RAR packages. According to reports, more than 1,600 suspicious emails were detected within a few weeks, indicating a large-scale operational development.

The chain of infection behind the attack

The infection chain starts with a PDF-bait containing embedded links or directly malicious binaries disguised as documents. The first stage activates a loader based on the Rust, a variant of the open source framework RustSL, which has been modified specifically for Silver Fox's needs.

This loader acts as a mechanism for decrypting and executing the next payload, while incorporating complex anti-analysis controls. It detects virtual environments, sandboxes and geographical parameters, avoiding execution in unwanted areas.

Of particular interest is the expansion of the geographical filtering list. While previous versions focused on China, newer versions now target India, Russia, Indonesia, South Africa, Cambodia, and Japan, revealing an international expansion strategy.

Silver Fox targets Russia and India with ABCDoor malware

Phantom Persistence: The new technique for staying in the system

One of the most worrying features of the campaign is the use of the Phantom Persistence, a method that allows the malware to remain active even after a system reboot.

The method exploits operating system update mechanisms , inserting malicious processes into the shutdown process. Essentially, the malware “convinces” the system that a reboot is required for the update, thus ensuring automatic execution at the next startup

See also: Silver Fox leverages Microsoft WatchDog to develop ValleyRAT

For security experts, this technique is considered extremely dangerous, as it bypasses several conventional endpoint protection detection mechanisms.

ValleyRAT and ABCDoor: A duo of advanced cyber espionage

After the initial infection, RustSL delivers the well-known ValleyRAT (or Winos 4.0), which acts as a basic command-and-control platform. From there, additional modules are loaded, most notably ABCDoor.

The new backdoor, written in Python, offers a full arsenal of remote control: taking screenshots, controlling the keyboard and mouse, managing files, terminating processes, collecting clipboard data, and remotely updating the malware itself.

Its modular architecture makes it highly flexible, allowing attackers to customize functionality depending on the target.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Silver Fox targets Russia and India with ABCDoor malware

The strategic evolution of Silver Fox

Analysts estimate that Silver Fox has now transformed into a hybrid cybercriminal entity, combining financial motives with pure espionage operations.

Since its first actions, which were mainly focused on China, the group has systematically expanded its activities to Taiwan, Japan, India and Russia, adopting increasingly sophisticated spear-phishing scenarios.

See also: Silver Fox Group Deploys Sainbox RAT via Fake Websites

The most worrying aspect is the adaptability of the attacks. The decoys are designed based on the tax periods, local administrative procedures and operational specificities of each country, dramatically increasing the success rates.

The Silver Fox case clearly shows that the new generation of cyber threats is not only based on technical sophistication, but also on a deep understanding of human behavior. For organizations and businesses, investing in staff training, advanced threat detection and zero-trust architectures is no longer an option, but an operational necessity.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS