The China-based group Silver Fox used phishing emails and a new malware called ABCDoor against organizations in Russia and India, with more than 1,600 malicious emails flagged in early 2026, according to a technical analysis by Kaspersky.
KEY FACTS
- Targets Organizations in industrial, consulting, retail and transportation sectors.
- Lures Tax notice emails impersonated India’s Income Tax Department and similar Russian entities.
- Malware chain The campaign used a Rust-based loader to drop ValleyRAT and then ABCDoor.
- Scope More than 1,600 phishing emails were detected between early January and early February.
- Capabilities ABCDoor can capture screenshots, manage files and processes, and exfiltrate clipboard data.
The report says the phishing waves began in December 2025 and used PDF files with links to ZIP or RAR archives hosted on abc.haijing88[.]com. In earlier cases, malicious code was embedded directly in the email attachments.
The archive contained an executable that mimicked a PDF file and used a modified version of the open-source RustSL loader. The loader checked for virtual machines and sandboxes, and it applied geofencing that covered countries including India, Indonesia, South Africa, Russia and Cambodia.
One variant also used Phantom Persistence to survive reboots by intercepting the shutdown process and forcing the system to restart under the guise of an update. The loaded payload then downloaded ValleyRAT, whose core component handled command and control, command execution and additional modules.
ABCDoor had been part of the group’s toolkit since at least December 19, 2024 and was used in attacks starting in early 2025, the disclosure said. Kaspersky also noted that Silver Fox had used a JavaScript loader to deliver ABCDoor in November 2025, while newer RustSL versions expanded the focus to Japan.
WHY IT MATTERS
The campaign shows how phishing emails, loaders and backdoors can be combined to reach multiple sectors across several countries. The geofencing and persistence features also suggest a targeted effort to limit exposure while keeping access on compromised systems.

