PULSE NAME
Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and India
WHITE Silver Fox AlienVault 2026-04-30 Modified: 2026-05-30
144
IOCs
HIGH VOLUME
The Silver Fox threat group conducted phishing campaigns in December 2025 and January 2026, impersonating tax authorities in India and Russia. Malicious emails contained archives with a modified Rust-based RustSL loader that deployed ValleyRAT backdoor. Over 1600 malicious emails targeted organizations across industrial, consulting, retail, and transportation sectors. During investigation, a previously undocumented Python-based backdoor named ABCDoor was discovered, active since late 2024. The attacks utilized multi-stage infection chains involving encrypted payloads, custom ValleyRAT modules, and various persistence mechanisms including Phantom Persistence technique. ABCDoor features remote control capabilities, screen broadcasting using ffmpeg, and file manipulation functions. The group employed sophisticated evasion techniques including geofencing, string encryption, and mimicking legitimate VPN services.
Indicators of Compromise (21 / 144 total)
All URL FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 0ac6b8a5f0572b82f6483f2dff2d1535e3da55f0 2026-04-30
FileHash-SHA1 0dc9684946142d231f75ed2c9ce1f7ebc38b39f4 2026-04-30
FileHash-SHA1 0e8c2c75d3dd4b670b8d035d5f645c74f5455c02 2026-04-30
FileHash-SHA1 12e41cc25fe8e99a0fca691fb88ed9823e989853 2026-04-30
FileHash-SHA1 1d28c9073fb89c09cd34ea3592d6654832e45a14 2026-04-30
FileHash-SHA1 25818cdcfb39eaa22d999d214e6159417cfba72e 2026-04-30
FileHash-SHA1 2c2ebe8f78f1a4143e6a125adb7a4efd2aebc275 2026-04-30
FileHash-SHA1 34d792d07092d963375e336869c9f40296858345 2026-04-30
FileHash-SHA1 34d7aa9cf1fceab7f221891f7fbc23157bd9f65b 2026-04-30
FileHash-SHA1 38a03f625cd9de3086a7ea6759c0b46115a0525b 2026-04-30
FileHash-SHA1 895aebe2d281e66f87963c01de570286561a0de2 2026-04-30
FileHash-SHA1 8c29a2693ddf208455db290abfc76c153da27643 2026-04-30
FileHash-SHA1 96ea4a649f67272e305b75401a4045efae91c926 2026-04-30
FileHash-SHA1 9a6c59eaa1d467029c8e1fee651b6d09ddde91e4 2026-04-30
FileHash-SHA1 a00e86ee1c4a1318ae394d3927d01f5aec74f861 2026-04-30
FileHash-SHA1 acbdc1781a5a62789fdd233cde9c6521500f66f2 2026-04-30
FileHash-SHA1 ad94d5ee63f405eb6a1a157713aa6999e579c6e6 2026-04-30
FileHash-SHA1 bb88f63ba7762b7307251ab0e8bb544ccbaf9b52 2026-04-30
FileHash-SHA1 ca5c6fc9d9adc8e8edd474f601429764cc52d4b0 2026-04-30
FileHash-SHA1 f4d105f9565a8ee98e94d92e5a516e2f7b86e343 2026-04-30
FileHash-SHA1 fd4dba4c4493e6fe3045f9e47f63b6f8b256ac32 2026-04-30