Threats · 133 days ago
Silver Fox is using tax-themed lures to turn a simple phishing email into a modular delivery system. The standard response misses the point: the lure is stable, but the payload can be swapped without changing the campaign’s outward shape.
Kaspersky says the group sent more than 1,600 malicious emails between early January and early February, targeting industrial, consulting, retail, and transportation organizations in India and Russia. The emails delivered a public Rust-based loader that fetched ValleyRAT, and in some cases a new ValleyRAT plugin that loaded the previously undocumented ABCDoor backdoor.
That modular setup makes the campaign harder to read from the lure alone. It also means defenders cannot assume the same attachment or payload will recur in the next wave.
3 sources covering this story
Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia
Silver Fox spreads ABCDoor via 1,600 phishing emails in 2026 targeting India and Russia, enabling data theft and remote control.
Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia
More than 1,600 malicious messages from the China-backed APT group deliver the previously undocumented ABCDoor backdoor and ValleyRAT malware.
Analyzing the Silver Fox tax campaign and the new ABCDoor backdoor
The Silver Fox group is targeting companies in Russia and India by impersonating tax authorities to distribute ValleyRAT and the new ABCDoor backdoor.
Part of the PlainSec briefing for 2026-05-05