Multiple reports say the China-based cybercrime group tracked as Silver Fox (also known by several aliases) is running a new set of phishing-driven intrusions targeting organizations in India and Russia. The campaign uses messages designed to look like correspondence related to India’s Income Tax Department, with activity reported around December 2025. Victims are sent socially engineered emails, and the messages are used to deliver malware believed to include ABCDoor, which researchers describe as a previously undocumented backdoor, along with additional payloads such as ValleyRAT and other malware families.
One report describes the campaign as involving more than 1,600 socially engineered messages aimed at organizations across multiple sectors. Another report focuses on how the phishing lures are tailored to the tax theme and linked to the delivery of ABCDoor. Across both accounts, the reporting emphasizes the group’s ongoing development and use of phishing to establish malware access on targeted systems, and it places the incidents in the Indian and Russian targeting footprint described by threat researchers.