Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and India
2026-04-30T20:52:03Z•5f180a2048c0d51e65f3d52a032884c05195e5662dd8bf648d7aeafc5e4e414e
ABCDoorAPTApp StoreClipBankerCrystalXFakeWalletICS threats Q4 2025 reportJanelaRATLiteLLMMaaSPhantomRPCRATSilver FoxValleyRATWindows RPCclipboard hijackercrypto stealerfinancial malwareiOSindustrial control systemsphishingprivilege escalationsupply chaintax-themed luretrojanized software
What happened
Kaspersky Securelist articles (Apr 2026) describe multiple active threats and notable vulnerabilities: the Silver Fox group is impersonating tax authorities to deliver ValleyRAT and a new ABCDoor backdoor targeting organizations in Russia and India; a newly reported Windows RPC privilege-escalation technique (PhantomRPC); an iOS-targeting FakeWallet crypto stealer distributed via App Store phishing apps; several financial malware campaigns (JanelaRAT, ClipBanker) and a new CrystalX RAT offered as MaaS; a supply-chain compromise of the LiteLLM AI gateway; industrial automation threat statistics
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 5f180a2048c0d51e65f3d52a032884c05195e5662dd8bf648d7aeafc5e4e414e
- Enrichment time
- 2026-04-30T20:52:03Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.