SilverFox hackers deploy fake Claude apps to infiltrate companies across Asia, Kaspersky warns

2 Sources

Share

Kaspersky researchers uncovered SilverFox, one of Asia Pacific's most active advanced persistent threat groups, distributing fake Claude AI applications for Windows, macOS, and Linux to infiltrate organizations. The campaign primarily targets Greater China, accounting for over 90% of attacks, with manufacturing, IT services, healthcare, and finance sectors most at risk.

News article

SilverFox Emerges as Major Threat to Asian Businesses

Kaspersky's Global Research and Analysis Team (GReAT) identified SilverFox as one of the most active advanced persistent threat groups operating in Asia Pacific, exploiting the growing adoption of artificial intelligence in businesses. First detected in December 2025, SilverFox has rapidly escalated its operations by distributing fake Claude apps across Windows, macOS, and Linux platforms to target companies in Asia

1

. The group infiltrates organizations through three primary vectors: fake websites, phishing emails, and malicious files distributed via social messaging apps

2

.

Ye Jin (Seth), Lead Security Researcher at Kaspersky GReAT, emphasized the group's sophistication: "They inject malware used for long-term cyberespionage and sensitive data gathering. Our recent analysis showed they are now distributing fake Claude for Windows, macOS, and Linux, leveraging AI use in companies to crack into their targets' security defenses"

2

. This exploitation of AI-themed lures represents a calculated shift in social engineering tactics, capitalizing on organizations' rush to adopt AI tools.

Greater China Bears the Brunt of Attacks

The geographic concentration of SilverFox operations reveals a clear pattern. Greater China represents more than 90% of all attacks, with mainland China alone accounting for 71% of malicious activity

1

. Myanmar, Cambodia, and Singapore have emerged as the next hotspots requiring heightened vigilance

2

. Recent campaigns extended beyond Asia, targeting companies in India, Indonesia, South Africa, and Russia across industrial, consulting, trade, and transportation sectors

1

.

The Asia Pacific region experiences a volume of SilverFox activity far exceeding all other regions combined, indicating the group's concentrated focus on East and Southeast Asian targets

2

. This geographic targeting suggests either regional infrastructure vulnerabilities or specific intelligence objectives driving the campaign.

Manufacturing and IT Services Face Highest Risk

Manufacturing makes up more than one-third of all SilverFox attacks, establishing it as the top target industry

2

. IT services follow closely behind, with researchers observing substantial phishing aimed at tech workers

2

. Healthcare and finance sectors also face significant risks from this group known for pursuing high-value targets

1

.

In one documented campaign, attackers sent phishing emails disguised as official tax audit notifications, prompting recipients to download an archive purportedly containing a "list of tax violations." Kaspersky recorded more than 1,600 malicious emails between January and February 2026

1

. This tactic leverages the perceived authority and urgency of communications from tax agencies to persuade victims to trigger the attack chain

2

.

AI-Assisted Malware Transforms Attack Landscape

Kaspersky researchers warned that artificial intelligence is fundamentally lowering the cost and technical expertise required to launch sophisticated cyberattacks

1

. The emergence of JADEPUFFER, described as the world's first fully LLM-driven ransomware, marked a significant turning point in cyber threats. Unlike previous attacks where AI merely augmented human operators, JADEPUFFER demonstrated AI acting as both decision-maker and executor

2

.

In a case disclosed by Sysdig, a malicious AI agent completed the entire cycle of diagnosing a failed attempt, correcting its approach, and launching a new attack in just 31 seconds

1

. This speed far outpaces the response capabilities of most human defenders, demonstrating an unprecedented level of autonomy where AI agents replicate the reasoning of experienced attackers without direct oversight

2

.

VoidLink, an AI-assisted cloud-native malware framework identified in January 2026, provides further evidence that generative AI is making sophisticated malware development more accessible

1

. Kaspersky also highlighted ChatGPhish, an indirect prompt injection technique that hides malicious instructions inside webpages. When users ask an AI assistant to summarize such content, the AI can unknowingly relay malicious instructions or links

1

.

Defense Strategies Must Match Attack Sophistication

Kaspersky recommended that companies deploy AI-driven threat hunting, Zero Trust architecture, comprehensive protection across endpoints and networks, and AI-based detection and response to counter increasingly automated attacks

1

. "As attackers can leverage AI to automate decision-making and accelerate every stage of an attack, defenders must respond with the same level of intelligence," Ye Jin stated

1

.

The SilverFox campaign employs a multi-stage approach to payload delivery and utilizes segmented infrastructure, using different addresses and domains for various attack stages. These techniques minimize detection risk and prevent blocking of the entire attack chain

2

. Organizations must recognize that cyberattacks are evolving from specialized team operations to low-cost solo raids enabled by AI capabilities, fundamentally changing the threat landscape they face.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved