PULSE NAME
Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and India
WHITE Silver Fox AlienVault 2026-04-30 Modified: 2026-05-30
144
IOCs
HIGH VOLUME
The Silver Fox threat group conducted phishing campaigns in December 2025 and January 2026, impersonating tax authorities in India and Russia. Malicious emails contained archives with a modified Rust-based RustSL loader that deployed ValleyRAT backdoor. Over 1600 malicious emails targeted organizations across industrial, consulting, retail, and transportation sectors. During investigation, a previously undocumented Python-based backdoor named ABCDoor was discovered, active since late 2024. The attacks utilized multi-stage infection chains involving encrypted payloads, custom ValleyRAT modules, and various persistence mechanisms including Phantom Persistence technique. ABCDoor features remote control capabilities, screen broadcasting using ffmpeg, and file manipulation functions. The group employed sophisticated evasion techniques including geofencing, string encryption, and mimicking legitimate VPN services.
Indicators of Compromise (21 / 144 total)
All URL FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 0cffb8b8fd11f300b5477ff23ec576f66ab65c021d995fa5495827237e679d93 2026-04-30
FileHash-SHA256 0eb664b45200c9b4e954162128d2c13bc693f6ae57650b49a3a9fb9b2e821110 2026-04-30
FileHash-SHA256 285c764e84ca830d90e75df06ee5445693f79058142b85b5e054c5c78c0421aa 2026-04-30
FileHash-SHA256 3296bd88e0a85ebad4f429878bf8bca16ac43e609133b4781f88a339c37bfe9f 2026-04-30
FileHash-SHA256 4518249127a023adb81d232452395e1506a3766eac1664b8a63c3d0e7dcc2dc2 2026-04-30
FileHash-SHA256 4b4dcbd26f08dca7e3e5721f0f5bdc6274e1edc0556e0749a426ec22ff83ca10 2026-04-30
FileHash-SHA256 56366c635d7b2ae88e8c8e9511f0c12e1cf1173b8be8c8f211b38a26d3a21e1c 2026-04-30
FileHash-SHA256 5be9fc4ad9ae3e791d18427f4592c234dfb612aec39b219e8ec57424f61cbab3 2026-04-30
FileHash-SHA256 5d8c7fffc0992639edbca893366f19d5784af2d77e3cfcbaa445a10c503f935a 2026-04-30
FileHash-SHA256 67c87dafb26de3b2b15b93a4ccd291e95682b9adf4ecb083b7c54286245ebd87 2026-04-30
FileHash-SHA256 795f939f8b9a2d56a3e8a609cab81032d9122a7d56ea852d95cd668f09139a3a 2026-04-30
FileHash-SHA256 905efac09785631ed57e57a6236b87c04f53b9e0a3bf697df71365814dee6362 2026-04-30
FileHash-SHA256 949b0bea5bd7feab58e280dde49310521920b655714c5f1b7d9de8719373dcd7 2026-04-30
FileHash-SHA256 a553833771f3e75ec3132f1295284e0e885e048b288f37ff8546677e5cb42f2f 2026-04-30
FileHash-SHA256 c925048d6da2a2cd30ad521c1153f56366ee4bacbe84c8b929c1be7f9f2aa445 2026-04-30
FileHash-SHA256 d8f9f8bc811f428dd9605000470c5f496f46145e2d3d8b7e750bca901e55fcdd 2026-04-30
FileHash-SHA256 dbfa683cd8c600ed0e90f58eb965ca38b1561fa99d12cb7f252e8608da217df2 2026-04-30
FileHash-SHA256 e96091fd784eca3c56ce4a703b22f5e5941464aec32a6f356ad0f99ea4422f04 2026-04-30
FileHash-SHA256 f0e4d25b9b707be029e915ecb9fe61132cce89e138de36fef5e1edef551d7c25 2026-04-30
FileHash-SHA256 fedf8678350dd29713be43f6115a2a8361f011b4b2eaf51e57eb2ffd758caa83 2026-04-30
FileHash-SHA256 ffaea868dc1d68211664133e3b69f7025f1406bd4647d77f3aee945d745ad4bc 2026-04-30