Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and India

2026-04-30T08:52:15Z06164b7b242c88ad3e9cf862677a0588e6035b2a2f43448ae6d9ecb0089d38cc
ABCDoorAPTApp StoreClipBankerCorunaCrystalXFakeWalletJanelaRATLiteLLMMaaSOperation TriangulationPhantomRPCRATSilver FoxValleyRATWindows RPCclipboard hijackercrypto stealerexploit kit','kernel exploitiOSphishingprivilege escalationsupply chaintax-themedtrojanized Proxifier

What happened

Kaspersky Securelist published multiple investigations covering active threat campaigns, vulnerabilities and industry reports: the Silver Fox APT is running a tax-notification phishing campaign in Russia and India delivering ValleyRAT and a new ABCDoor backdoor; a newly reported PhantomRPC weakness in Windows RPC enables creation of fake RPC servers for local privilege escalation; FakeWallet credential/crypto stealers were distributed via >20 malicious iOS App Store apps; Q4 2025 industrial automation threat statistics and a 2025 financial-threat overview highlight continued targeting of ICS/fi

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
06164b7b242c88ad3e9cf862677a0588e6035b2a2f43448ae6d9ecb0089d38cc
Enrichment time
2026-04-30T08:52:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and India · Baitaphish