Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and India
2026-04-30T08:52:15Z•06164b7b242c88ad3e9cf862677a0588e6035b2a2f43448ae6d9ecb0089d38cc
ABCDoorAPTApp StoreClipBankerCorunaCrystalXFakeWalletJanelaRATLiteLLMMaaSOperation TriangulationPhantomRPCRATSilver FoxValleyRATWindows RPCclipboard hijackercrypto stealerexploit kit','kernel exploitiOSphishingprivilege escalationsupply chaintax-themedtrojanized Proxifier
What happened
Kaspersky Securelist published multiple investigations covering active threat campaigns, vulnerabilities and industry reports: the Silver Fox APT is running a tax-notification phishing campaign in Russia and India delivering ValleyRAT and a new ABCDoor backdoor; a newly reported PhantomRPC weakness in Windows RPC enables creation of fake RPC servers for local privilege escalation; FakeWallet credential/crypto stealers were distributed via >20 malicious iOS App Store apps; Q4 2025 industrial automation threat statistics and a 2025 financial-threat overview highlight continued targeting of ICS/fi
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 06164b7b242c88ad3e9cf862677a0588e6035b2a2f43448ae6d9ecb0089d38cc
- Enrichment time
- 2026-04-30T08:52:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.