Silver Fox Launches ABCDoor Campaign Targeting Russia and India via Phishing
Block ABCDoor phishing emails and monitor for related malware.
Configure email filtering to block ABCDoor phishing campaigns.
Summary
The China‑based cybercrime group Silver Fox has launched a new campaign targeting organizations in Russia and India with a malware package called ABCDoor. The attack vector involves phishing emails that impersonate correspondence from the Indian Income Tax Department, sent in December 2025. A subsequent wave targeted Russian entities using a similar spoofed email strategy. Both campaigns followed nearly identical patterns, including the use of malicious attachments and links to a compromised download site. ABCDoor is designed to establish persistence on infected hosts and exfiltrate sensitive data. The malware leverages social engineering to bypass email security controls. The campaign highlights the continued threat posed by state‑aligned threat actors in the region.
Key changes
- Silver Fox launched campaign targeting Russia and India with ABCDoor malware.
- Phishing emails mimic Indian Income Tax Department, sent Dec 2025.
- Similar wave targeted Russian entities using spoofed emails.
- Both campaigns use malicious attachments and links to compromised download site.
- ABCDoor establishes persistence and exfiltrates sensitive data.
- Attack leverages social engineering to bypass email security.