Threats & Adversaries · APT / Espionage
Tax Phishing Delivers Swappable Malware in India and Russia Silver Fox is using tax-themed lures to turn a simple phishing email into a modular delivery system. The standard response misses the point: the lure is stable, but the payload can be swapped without changing the campaign’s outward shape.
Kaspersky says the group sent more than 1,600 malicious emails between early January and early February, targeting industrial, consulting, retail, and transportation organizations in India and Russia. The emails delivered a public Rust-based loader that fetched ValleyRAT, and in some cases a new ValleyRAT plugin that loaded the previously undocumented ABCDoor backdoor.
That modular setup makes the campaign harder to read from the lure alone. It also means defenders cannot assume the same attachment or payload will recur in the next wave.
3 sources · May 4
Timeline Sources May 4 The Hacker News
Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia
Silver Fox spreads ABCDoor via 1,600 phishing emails in 2026 targeting India and Russia, enabling data theft and remote control.
original May 4 Dark Reading
Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia
More than 1,600 malicious messages from the China-backed APT group deliver the previously undocumented ABCDoor backdoor and ValleyRAT malware.
original Apr 30 Kaspersky Securelist
Analyzing the Silver Fox tax campaign and the new ABCDoor backdoor
The Silver Fox group is targeting companies in Russia and India by impersonating tax authorities to distribute ValleyRAT and the new ABCDoor backdoor.
original Part of the PlainSec briefing for 2026-05-05
Every edition of this story: Tax Phishing Delivers Swappable Malware in India and Russia
More from today
Threats & Adversaries · APT / Espionage
Tax Phishing Delivers Swappable Malware in India and Russia Silver Fox is using tax-themed lures to turn a simple phishing email into a modular delivery system. The standard response misses the point: the lure is stable, but the payload can be swapped without changing the campaign’s outward shape.
Kaspersky says the group sent more than 1,600 malicious emails between early January and early February, targeting industrial, consulting, retail, and transportation organizations in India and Russia. The emails delivered a public Rust-based loader that fetched ValleyRAT, and in some cases a new ValleyRAT plugin that loaded the previously undocumented ABCDoor backdoor.
That modular setup makes the campaign harder to read from the lure alone. It also means defenders cannot assume the same attachment or payload will recur in the next wave.
3 sources · May 4
Timeline Sources May 4 The Hacker News
Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia
Silver Fox spreads ABCDoor via 1,600 phishing emails in 2026 targeting India and Russia, enabling data theft and remote control.
original May 4 Dark Reading
Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia
More than 1,600 malicious messages from the China-backed APT group deliver the previously undocumented ABCDoor backdoor and ValleyRAT malware.
original Apr 30 Kaspersky Securelist
Analyzing the Silver Fox tax campaign and the new ABCDoor backdoor
The Silver Fox group is targeting companies in Russia and India by impersonating tax authorities to distribute ValleyRAT and the new ABCDoor backdoor.
original Part of the PlainSec briefing for 2026-05-05
Every edition of this story: Tax Phishing Delivers Swappable Malware in India and Russia
More from today