Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia

2026-05-04T14:51:44Z014989fd135e3162bd20b13993c9d587dc263eaba3c8cb31420cab133e4531a4
ABCDoorChina‑backed APTIndiaRussiaSilver FoxValleyRATbackdoorespionagemalwarephishingsocial engineeringtax lurethreat intelligence

What happened

A China‑backed APT tracked as "Silver Fox" ran a large tax‑themed social‑engineering campaign (over 1,600 messages) targeting organizations across India and Russia. The campaign delivered multiple tools including a previously undocumented backdoor dubbed ABCDoor, the ValleyRAT remote access trojan, and other malware to establish persistent access, credential theft, and data exfiltration. The attacks used tailored lures and widespread phishing to hit multiple sectors, indicating an espionage‑oriented, scalable operation.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
014989fd135e3162bd20b13993c9d587dc263eaba3c8cb31420cab133e4531a4
Enrichment time
2026-05-04T14:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.