The China-based cybercrime group known as Silver Fox has been linked to a new campaign targeting organizations in Russia and India with a new malware called ABCDoor. The activity involved using phishing emails that mimic correspondence from the Income Tax Department of India in December 2025, followed by a similar campaign aimed at Russian entities in January 2026.
The Attack Chain
Both waves followed a nearly identical structure: phishing emails were styled as official notices regarding tax audits or prompted users to download an archive containing a “list of tax violations.” Inside the archive was a modified Rust-based loader pulled from a public repository. This loader would download and execute the well-known ValleyRAT backdoor.
The campaign is estimated to have impacted organizations across the industrial, consulting, retail, and transportation sectors. More than 1,600 phishing emails were flagged between early January and early February 2026.
Tax-Themed Lures
The starting point of the attack chain is a phishing email containing a PDF file, which features two clickable links that lead to the download of a ZIP or RAR archive hosted on “abc.haijing88[.]com.” In the campaign detected in December 2025, the malicious code was embedded directly within the files attached to the email.
Present within the archive is an executable that mimics a PDF file. The binary is a modified version of an open-source shellcode loader and antivirus bypass framework called RustSL (Rust Shellcode Loader). Silver Fox’s first recorded use of RustSL dates back to late December 2025.
RustSL Loader: Modified for Evasion
The end goal of the Silver Fox RustSL variant is to unpack the encrypted malicious payload, while implementing country-based geofencing and environment checks to detect virtual machines and sandboxes. While the GitHub variant only includes China in its country list, the bespoke version features:
- India
- Indonesia
- South Africa
- Russia
- Cambodia
- Japan (added in newer versions)
This geofencing ensures the malware only executes in target countries, avoiding analysis environments and reducing detection risk.
Phantom Persistence: A Novel Technique
One variant of the loader employs a novel method called Phantom Persistence to establish persistence on the compromised host. First documented in June 2025, this technique abuses functionality designed to allow applications requiring a reboot for updates to complete the installation process properly.
Kaspersky explained: “The attackers intercept the system shutdown signal, halt the normal shutdown sequence, and trigger a reboot under the guise of an update for the malware. Consequently, the loader forces the system to execute it upon OS startup.”
This means the malware survives reboots by disguising itself as a legitimate system update, making it extremely difficult for users to remove through conventional means.
ValleyRAT and ABCDoor Backdoor
The encrypted payload loaded by RustSL results in the download of the encrypted ValleyRAT (aka Winos 4.0) malware. The core component (“login-module.dll_bin”) is responsible for:
- Command-and-control (C2) communications
- Command execution
- Retrieval and execution of additional modules
One of the custom modules deployed as part of the attack following a second geofencing check is ABCDoor, a previously undocumented Python-based backdoor. The backdoor has been part of the threat actor’s arsenal since at least December 19, 2024, and was put to use in cyber attacks beginning February or March 2025.
ABCDoor Capabilities
ABCDoor contacts an external server via HTTPS and processes incoming messages to facilitate:
- Persistence: Maintaining long-term access to compromised systems
- Backdoor Updates: Self-updating and removal capabilities
- Data Collection: Screenshots, clipboard contents, file system operations
- Remote Control: Mouse and keyboard control from attacker’s end
- Process Management: Starting, stopping, and monitoring system processes
- File Operations: Uploading, downloading, and deleting files on victim systems
Geographic Targeting
The highest number of attacks has been detected in:
- India
- Russia
- Indonesia
- South Africa
- Japan
The majority of loader samples discovered have employed tax-themed lures to imitate the infection sequence. As recently as November 2025, Silver Fox was observed using a JavaScript loader to deliver ABCDoor, with the loader distributed via self-extracting (SFX) archives packaged inside ZIP archives sent via phishing emails.
Silver Fox: Dual-Track Operations
According to S2W, “Since 2024, Silver Fox has evolved into a dual-track operational model that simultaneously conducts profitable extensive opportunistic activities and espionage activities.” In the early stages, the group targeted China for attacks, but later expanded its operational scope to Taiwan and Japan.
The Silver Fox group primarily utilizes highly customized spear phishing techniques for initial infiltration, deploying sophisticated and diversified attack scenarios tailored to:
- Seasonal issues of the target country
- Target’s work characteristics
- Industry-specific themes (tax, finance, government)
Why This Matters
This campaign highlights several critical trends:
- Open-Source Weaponization: Silver Fox modifies publicly available tools (RustSL from GitHub) for malicious purposes, lowering the barrier to advanced malware development
- Geofencing Evasion: Country-specific execution prevents analysis in security research environments outside target regions
- Persistence Innovation: Phantom Persistence represents a new class of reboot-survival techniques that abuse legitimate Windows update mechanisms
- Modular Architecture: ValleyRAT serves as a platform for deploying additional payloads like ABCDoor, enabling flexible, multi-stage attacks
- Seasonal Targeting: Tax-themed lures exploit time-sensitive concerns, increasing the likelihood of victim compliance
Protection Measures
For Organizations:
- Implement email authentication (DMARC, SPF, DKIM) to reduce phishing success
- Block executable attachments (ZIP, RAR, EXE) from external sources
- Deploy endpoint detection and response (EDR) solutions capable of detecting Rust-based loaders
- Monitor for unusual shutdown/reboot sequences that may indicate Phantom Persistence
- Conduct regular security awareness training focused on tax-themed and government impersonation lures
- Restrict PowerShell and Python execution to authorized users only
For Users:
- Verify tax-related communications directly through official government portals
- Never click links or download attachments from unsolicited tax notices
- Be skeptical of urgent language demanding immediate action
- Report suspicious emails to your IT security team immediately
Indicators of Compromise (IOCs)
Organizations should monitor for the following indicators:
- Domain: abc.haijing88[.]com
- File names mimicking PDF documents but with executable extensions
- RustSL-based loaders with geofencing checks for India, Russia, Indonesia, South Africa, Cambodia, Japan
- ValleyRAT/Winos 4.0 C2 communications
- ABCDoor Python backdoor artifacts in system processes
- Unexpected system reboot prompts following email attachment execution
Broader Implications
Silver Fox’s evolution from regional Chinese threat actor to international cybercrime group demonstrates the increasing sophistication and commercialization of state-aligned cyber operations. The group’s ability to customize attacks based on seasonal and regional themes, combined with their use of advanced persistence techniques and modular malware architectures, positions them as a significant threat to organizations in targeted countries.
The use of tax-themed lures is particularly insidious, as it exploits universal concerns about financial compliance and regulatory penalties. As tax seasons approach in various countries, organizations should heighten their vigilance against similar campaigns.