Silver Fox Campaign Deploys ValleyRAT Through Tax-Themed Lures

Between late 2025 and early 2026, a sophisticated phishing campaign attributed to the Chinese-affiliated Advanced Persistent Threat (APT) group known as Silver Fox actively targeted organizations in India and Russia.

By disguising malicious emails as official correspondence from national tax authorities, the attackers successfully breached networks across the industrial, consulting, retail, and transportation sectors.

The threat actor is known to conduct highly targeted operations timed to coincide with regional tax deadlines.

This dual-pronged campaign utilized a highly modified Rust-based loader to deploy the notorious ValleyRAT backdoor.

Advanced Delivery and The Custom RustSL Loader

The attack chain begins with tax-themed phishing emails designed to alarm victims with notices of tax audits or violations. In the December 2025 wave targeting India, emails contained RAR archives that embedded malicious executables, masked as PDF icons.

By January 2026, the campaign targeting Russian entities shifted tactics slightly, utilizing PDF attachments containing external download links.

This strategy effectively bypassed traditional email security gateways, delivering a malicious ZIP archive directly to the victim’s device.

Phishing email sent to victims in Russia (Source: securelist)
Phishing email sent to victims in Russia (Source: securelist)

Deployment of ValleyRAT and The Novel ABCDoor Backdoor

Upon successful execution, the RustSL loader decrypts and runs shellcode that connects to the attacker’s infrastructure.

This downloads the ValleyRAT, also known as Winos 4.0, backdoor components directly into memory.

ValleyRAT acts as the primary foothold, managing command-and-control communications and establishing registry-based persistence to ensure continuous deep system compromise.

Contents of the PDF file from the January phishing wave (Source: securelist)
Contents of the PDF file from the January phishing wave (Source: securelist)

During the investigation, security researchers uncovered that ValleyRAT was downloading custom auxiliary plugins.

These plugins performed additional geofencing checks before retrieving a massive 52-megabyte archive containing a Python environment and the newly discovered ABCDoor backdoor.

Contents of the фнс.zip archive (Source: securelist)
Contents of the фнс.zip archive (Source: securelist)

ABCDoor represents a unique approach to post-compromise control. Unlike traditional backdoors that offer reverse shells or arbitrary command execution, ABCDoor relies entirely on visual remote control.

It utilizes a bundled, statically linked version of the legitimate ffmpeg.exe utility to broadcast the victim’s screen back to the attackers via the Desktop Duplication API.

Attackers then remotely manipulate the infected system by emulating double-clicks and keyboard inputs.

Operating silently within a legitimate pythonw.exe background process, ABCDoor uses asynchronous HTTPS communication and features advanced capabilities such as DPAPI file encryption, clipboard theft, and self-updating mechanisms.

The integration of the customized RustSL loader securelist, the established ValleyRAT, and the innovative ABCDoor demonstrates the growing technical maturity of the Silver Fox APT group.

By exploiting seasonal tax themes and employing complex, multi-stage delivery chains, this threat actor poses a critical risk to global enterprises.

Organizations must enhance endpoint detection capabilities, monitor for unusual Python process activity, and maintain rigorous employee training on phishing to defend against these targeted espionage campaigns.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories