Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and India
· Published 30/04/2026 09:42 · Modified 04/05/2026 11:00
Essential information
- Published
- 30/04/2026 09:42
- Modified
- 04/05/2026 11:00
- Tags
- 2026-04-30 abcdoor python backdoor silver fox valleyrat winos 4.0
- Related entities
- 46 observables, 1 intrusion sets (apt), 19 techniques (mitre), 4 malware, 26 others
Description
The Silver Fox threat group conducted phishing campaigns in December 2025 and January 2026, impersonating tax authorities in India and Russia. Malicious emails contained archives with a modified Rust-based RustSL loader that deployed ValleyRAT backdoor. Over 1600 malicious emails targeted organizations across industrial, consulting, retail, and transportation sectors. During investigation, a previously undocumented Python-based backdoor named ABCDoor was discovered, active since late 2024. The attacks utilized multi-stage infection chains involving encrypted payloads, custom ValleyRAT modules, and various persistence mechanisms including Phantom Persistence technique. ABCDoor features remote control capabilities, screen broadcasting using ffmpeg, and file manipulation functions. The group employed sophisticated evasion techniques including geofencing, string encryption, and mimicking legitimate VPN services.
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Observables (46)
108.187.42.6357.133.212.10645.192.219.60207.56.138.28192.163.167.14207.56.119.216108.187.41.221154.82.81.205154.82.81.192108.187.37.85192.229.115.229192.238.205.47http://154.82.81.205/YD20251001143052.zip'https://mcagov.cc/download.php?type=exe.https://sudsmama.com/api/download/c8ea0a2c-42c2-4159-9337-ee774ed5e7cbhttps://sudsmama.com/api/download/50e24b3a-8662-4d2f-9837-8cc62aa8f697https://abc.fetish-friends.com/setup/installhttps://abc.fetish-friends.com/setup?channel=jiqi_0819https://roldco.com/api/download/c51bbd17-ef08-4d6c-ab4c-d7bf49483dd6https://abc.fetish-friends.com/uploads/appclient.ziphttps://abc.fetish-friends.com/setup/install?channel=whatsapp_0826https://vnc.kcii2.comhttp://154.82.81.205/YN20250923193706.zip.http://154.82.81.205/YD20251001143052.ziphttps://abc.fetish-friends.com/setup/install?channel=dianhua-09030eb664b45200c9b4e954162128d2c13bc693f6ae57650b49a3a9fb9b2e8211103296bd88e0a85ebad4f429878bf8bca16ac43e609133b4781f88a339c37bfe9fe96091fd784eca3c56ce4a703b22f5e5941464aec32a6f356ad0f99ea4422f04905efac09785631ed57e57a6236b87c04f53b9e0a3bf697df71365814dee63624518249127a023adb81d232452395e1506a3766eac1664b8a63c3d0e7dcc2dc267c87dafb26de3b2b15b93a4ccd291e95682b9adf4ecb083b7c54286245ebd87795f939f8b9a2d56a3e8a609cab81032d9122a7d56ea852d95cd668f09139a3a4b4dcbd26f08dca7e3e5721f0f5bdc6274e1edc0556e0749a426ec22ff83ca105d8c7fffc0992639edbca893366f19d5784af2d77e3cfcbaa445a10c503f935affaea868dc1d68211664133e3b69f7025f1406bd4647d77f3aee945d745ad4bcdbfa683cd8c600ed0e90f58eb965ca38b1561fa99d12cb7f252e8608da217df2949b0bea5bd7feab58e280dde49310521920b655714c5f1b7d9de8719373dcd70cffb8b8fd11f300b5477ff23ec576f66ab65c021d995fa5495827237e679d93f0e4d25b9b707be029e915ecb9fe61132cce89e138de36fef5e1edef551d7c25c925048d6da2a2cd30ad521c1153f56366ee4bacbe84c8b929c1be7f9f2aa4455be9fc4ad9ae3e791d18427f4592c234dfb612aec39b219e8ec57424f61cbab3d8f9f8bc811f428dd9605000470c5f496f46145e2d3d8b7e750bca901e55fcdd285c764e84ca830d90e75df06ee5445693f79058142b85b5e054c5c78c0421aafedf8678350dd29713be43f6115a2a8361f011b4b2eaf51e57eb2ffd758caa8356366c635d7b2ae88e8c8e9511f0c12e1cf1173b8be8c8f211b38a26d3a21e1ca553833771f3e75ec3132f1295284e0e885e048b288f37ff8546677e5cb42f2f
Intrusion sets (APT) (1)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 00:22 · Modified 21/12/2025 00:22
Techniques (MITRE) (19)
-
Virtualization/Sandbox Evasion
-
File Deletion
-
Process Injection
-
Encrypted Channel
-
Keylogging
-
Web Protocols
-
Data Encoding
-
Malicious File
-
Scheduled Task
-
Spearphishing Attachment
-
Native API
-
Obfuscated Files or Information
-
Remote Access Tools
-
Registry Run Keys / Startup Folder
-
Web Service
-
Deobfuscate/Decode Files or Information
-
File and Directory Discovery
-
Screen Capture
-
Clipboard Data
Malware (4)
Others (26)
- India
- British Indian Ocean Territory
- South Africa
- Japan
- Indonesia
- Russian Federation
- Manufacturing
- Retail
- Transportation
- uuid.rs
- vnc.kcii2.com
- abc.petitechanson.com
- obfuscate.io
- ipv4.rs
- abc.woopami.com
- abc.ilptour.com
- roldco.com
- abc.doublemobile.com
- guard.rs
- abc.sudsmama.com
- abc.3mkorealtd.com
- mcagov.cc
- abc.fetish-friends.com
- sudsmama.com
- steganography.rs
- abc.haijing88.com