China-Based Silver Fox Group Deploys New ABCDoor Backdoor in Tax-Themed Campaign Targeting Russia and India
Kaspersky on May 4 reported a campaign by China-based
ABCDoor's Phantom Persistence mechanism signals design intent to survive first-responder containment rather than passive anti-analysis. Clipboard and screen-broadcasting capabilities profile it as a credential and document harvester consistent with the financial-intelligence logic of tax-authority impersonation. China simultaneously targeting Russia and India under unified campaign infrastructure reinforces documented patterns of Chinese intelligence collecting against nominally aligned states. Silver Fox's geofencing extension to Japan broadens the group's aperture toward U.S. alliance network targets. The 65 percent India detection skew, from a single Kaspersky report, may reflect Kaspersky's regional customer base rather than actual targeting priorities. Kaspersky's indicator publication now gives the research community a detection baseline, making additional public ABCDoor attribution
4 sources
- Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and India -
Kaspersky Securelist - Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia -
The Hacker News - Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia -
Dark Reading - Tax Audit Trap: Silver Fox Unleashes "ABCDoor" via Modified Rust Loaders -
Security Online