2 Sources
[1]
SilverFox hackers use fake Claude apps to target companies in Asia: Kaspersky
Cybersecurity group SilverFox is exploiting artificial intelligence across Asia Pacific. They distribute fake Claude AI applications for various operating systems. Kaspersky researchers identified SilverFox as a highly active threat group in the region. This group targets manufacturing, IT, healthcare, and finance sectors with sophisticated attacks. Cybersecurity threat group SilverFox is exploiting the growing use of artificial intelligence (AI) in businesses across Asia Pacific, including by distributing fake Claude AI apps for Windows, macOS and Linux, according to Kaspersky researchers. Kaspersky's Global Research and Analysis Team (GReAT) said SilverFox is among the most active advanced persistent threat (APT) groups in the region. The group uses fake websites, phishing emails and malicious files shared through social messaging apps to infiltrate organisations and steal sensitive data. "SilverFox is one of the most active threat groups in the whole APAC region," said Ye Jin (Seth), lead security researcher at Kaspersky GReAT. SilverFox was first identified by Kaspersky researchers in December 2025. Its recent campaigns targeted companies in India, Indonesia, South Africa and Russia, including those in industrial, consulting, trade and transportation sectors. In one campaign, attackers sent phishing emails disguised as tax audit notifications, asking recipients to download an archive supposedly containing a "list of tax violations". Kaspersky recorded more than 1,600 malicious emails between January and February 2026. China accounts for over 90% of SilverFox attacks The Asia Pacific region accounts for the bulk of SilverFox's malicious activity, with Greater China representing more than 90% of attacks and mainland China alone accounting for 71%, Kaspersky said. Manufacturing is the group's biggest target, accounting for more than a third of attacks. IT and services, healthcare and finance are also major targets. AI could make cyberattacks cheaper, faster Kaspersky warned that AI is lowering the cost and technical expertise needed to launch sophisticated cyberattacks. The researchers cited JADEPUFFER, described as the first fully LLM-driven ransomware, which demonstrated AI being used to make decisions and execute attacks with limited human intervention. In a case disclosed by Sysdig, a malicious AI agent diagnosed a failed attack, changed its approach and launched another attack in 31 seconds, Kaspersky said. The researchers also cited VoidLink, an AI-assisted cloud-native malware framework identified in January 2026, as evidence that generative AI can make sophisticated malware development more accessible. Kaspersky also highlighted ChatGPhish, an indirect prompt injection technique that hides malicious instructions inside webpages. When users ask an AI assistant to summarise such content, the AI can unknowingly relay the malicious instructions or links. Kaspersky calls for AI-powered defence Kaspersky recommended that companies use AI-driven threat hunting, Zero Trust architecture, comprehensive protection across endpoints and networks, and AI-based detection and response to counter increasingly automated attacks. "As attackers can leverage AI to automate decision-making and accelerate every stage of an attack, defenders must respond with the same level of intelligence," Ye Jin said.
[2]
Kaspersky GReAT: Top APT Group Targets APAC with Malware via Fake Claude App
Researcher from Kaspersky's Global Research and Analysis Team (GReAT) gave the lowdown on how SilverFox - one of the most active Advanced Persistent Threat (APT) groups - piggybacks on the rising Artificial Intelligence (AI) use in industries in Asia Pacific (APT). He also warns that fast-evolving Artificial Intelligence (AI) capabilities are ushering in an era where cyberattacks turn from "specialised team operations" to "low-cost solo raids". The GReAT researcher detailed the latest tactics being used by SilverFox, a major threat group active across the APAC region. The threat actor, detected by Kaspersky Global Research and Analysis Team (GReAT) researchers back in December 2025, is known for employing a multi-stage approach to payload delivery and utilises a segmented infrastructure, using different addresses and domains for various stages of the attack. These techniques are designed to minimise the risk of detection and prevent the blocking of the entire attack chain. Its most recent campaign targeted companies in India, Indonesia, South Africa and Russia across industrial, consulting, trade and transportation sectors, where it used phishing emails appearing as official tax audit notifications or to prompt recipients to download an archive purportedly containing a "list of tax violations." By leveraging the perceived authority and urgency of communications from tax agencies, the threat actor aimed to persuade victims to download the file and trigger the attack chain. Kaspersky's research recorded more than 1,600 malicious emails between January and February 2026. Now, recent findings from Kaspersky GReAT showed SilverFox is using fake Claude apps to infiltrate on their target organisations. Claude is an advanced conversational assistant, large language model (LLM), and chatbot developed by Anthropic. It helps users write, code, analyse long documents, and solve complex problems through natural dialogue. "SilverFox is one of the most active threat groups in the whole APAC region. They get into targets through three simple routes: fake websites, phishing emails, and harmful files spread via social messaging apps. They inject malware used for long-term cyberespionage and sensitive data gathering. Our recent analysis showed they are now distributing fake Claude for Windows, macOS, and Linux, leveraging AI use in companies to crack into their targets' security defenses," explains Ye Jin (Seth), Lead Security Researcher at Kaspersky GReAT. In terms of attack distribution, the APAC region is the hardest hit by SilverFox's malicious activities, with a volume far exceeding the sum of all other regions. This indicates that current SilverFox threats are mainly concentrated in Asia, particularly in East and Southeast Asia. "Based on our current threat data, Greater China is SilverFox's main target with over 90% of all its attacks targeting the region. Mainland China alone makes up 71%. Myanmar, Cambodia and Singapore also see lots of attacks. These are the next hotspots we need to watch," adds Ye Jin. When it comes to industry, manufacturing makes up more than one third of all attacks, making it the top target industry for SilverFox. IT and services are closely behind as Kaspersky GReAT researchers see a lot of phishing aimed at tech workers. Healthcare and finance also face big risks from the group known to go after high-value targets. AI attacks: speed, stealth, and accessibility Ye Jin also talked about JADEPUFFER, the world's first fully LLM-driven ransomware, which marked a significant turning point in cyber threats. Unlike previous attacks where AI merely augmented human operators, it demonstrated AI acting as both the decision-maker and executor. As the first agentic ransomware, JADEPUFFER redefined both the speed and sophistication of how cyberattacks happen using AI capabilities. Unlike conventional attacks that still rely on human operators to make decisions or adjust tactics, this attack showed a real-life example of how AI-powered threats can analyse, adapt, and execute attacks in real time. "In this particular case, disclosed by our Sysdig, the malicious AI agent completed the entire cycle of diagnosing a failed attempt, correcting its approach, and launching a new attack in just 31 seconds, far outpacing the response capabilities of most human defenders. Beyond speed, JADEPUFFER also demonstrates an unprecedented level of autonomy. It shows that AI agents are now capable of making independent decisions throughout the attack process, effectively replicating the reasoning of an experienced human attacker without direct oversight," he explains. Aside from speed and autonomy, the rise of agentic AI use in cyberattacks is also writing new rules in terms of stealth and accessibility. Ye Jin detailed the case of ChatGPhish, an indirect prompt injection technique that transforms trusted AI web-summarization features (like ChatGPT). In these attacks, cybercriminals hide malicious instructions inside webpages and trick users into asking an AI assistant to summarise the content. The AI then unknowingly relays the embedded malicious instructions or links, making it an unintended part of the attack. Because the malicious content is presented through a trusted AI interface, users are more likely to believe it is safe and click on harmful links or follow dangerous instructions. At the same time, these attacks are difficult for traditional security tools to detect, as they appear to be legitimate interactions between users and AI services rather than conventional cyberattacks. Malicious AI agents also eliminate the need for technical knowledge to wage a cyberattack. This was proven during the discovery of the AI and cloud-native malware framework VoidLink in January 2026. Unlike traditional malware that is largely written by human developers, VoidLink was reportedly developed almost entirely with the help of AI, demonstrating how generative AI is transforming the way sophisticated malware can be created and can be democratised. The need for AI-native defenses You fight fire with fire. And in this case, Kaspersky expert explains defenders can also utilise AI capabilities to protect enterprise and critical networks against AI-powered cyberattacks. The four ways companies can counter sophisticated AI-driven threats include: * Proactive defense - move beyond passive response and use AI-driven threat hunting to proactively find unknown threats * Zero Trust architecture - implement a Zero Trust architecture, verifying every access request strictly to eliminate internal network trust risks * Systematic Defense - build a comprehensive defense system covering endpoints, networks, applications, and data. * AI vs AI - use large models and dual-use AI technologies to enhance detection and response capabilities, and iterate in real-time with attackers. "When attackers can leverage AI to automate decision-making and accelerate every stage of an attack, defenders must respond with the same level of intelligence. Cybersecurity solutions enriched with continuously updated threat intelligence are no longer a competitive advantage, but a critical requirement for staying ahead of rapidly evolving threats," adds Ye Jin.
Share
Copy Link
Kaspersky researchers uncovered SilverFox, one of Asia Pacific's most active advanced persistent threat groups, distributing fake Claude AI applications for Windows, macOS, and Linux to infiltrate organizations. The campaign primarily targets Greater China, accounting for over 90% of attacks, with manufacturing, IT services, healthcare, and finance sectors most at risk.

Kaspersky's Global Research and Analysis Team (GReAT) identified SilverFox as one of the most active advanced persistent threat groups operating in Asia Pacific, exploiting the growing adoption of artificial intelligence in businesses. First detected in December 2025, SilverFox has rapidly escalated its operations by distributing fake Claude apps across Windows, macOS, and Linux platforms to target companies in Asia
1
. The group infiltrates organizations through three primary vectors: fake websites, phishing emails, and malicious files distributed via social messaging apps2
.Ye Jin (Seth), Lead Security Researcher at Kaspersky GReAT, emphasized the group's sophistication: "They inject malware used for long-term cyberespionage and sensitive data gathering. Our recent analysis showed they are now distributing fake Claude for Windows, macOS, and Linux, leveraging AI use in companies to crack into their targets' security defenses"
2
. This exploitation of AI-themed lures represents a calculated shift in social engineering tactics, capitalizing on organizations' rush to adopt AI tools.The geographic concentration of SilverFox operations reveals a clear pattern. Greater China represents more than 90% of all attacks, with mainland China alone accounting for 71% of malicious activity
1
. Myanmar, Cambodia, and Singapore have emerged as the next hotspots requiring heightened vigilance2
. Recent campaigns extended beyond Asia, targeting companies in India, Indonesia, South Africa, and Russia across industrial, consulting, trade, and transportation sectors1
.The Asia Pacific region experiences a volume of SilverFox activity far exceeding all other regions combined, indicating the group's concentrated focus on East and Southeast Asian targets
2
. This geographic targeting suggests either regional infrastructure vulnerabilities or specific intelligence objectives driving the campaign.Manufacturing makes up more than one-third of all SilverFox attacks, establishing it as the top target industry
2
. IT services follow closely behind, with researchers observing substantial phishing aimed at tech workers2
. Healthcare and finance sectors also face significant risks from this group known for pursuing high-value targets1
.In one documented campaign, attackers sent phishing emails disguised as official tax audit notifications, prompting recipients to download an archive purportedly containing a "list of tax violations." Kaspersky recorded more than 1,600 malicious emails between January and February 2026
1
. This tactic leverages the perceived authority and urgency of communications from tax agencies to persuade victims to trigger the attack chain2
.Related Stories
Kaspersky researchers warned that artificial intelligence is fundamentally lowering the cost and technical expertise required to launch sophisticated cyberattacks
1
. The emergence of JADEPUFFER, described as the world's first fully LLM-driven ransomware, marked a significant turning point in cyber threats. Unlike previous attacks where AI merely augmented human operators, JADEPUFFER demonstrated AI acting as both decision-maker and executor2
.In a case disclosed by Sysdig, a malicious AI agent completed the entire cycle of diagnosing a failed attempt, correcting its approach, and launching a new attack in just 31 seconds
1
. This speed far outpaces the response capabilities of most human defenders, demonstrating an unprecedented level of autonomy where AI agents replicate the reasoning of experienced attackers without direct oversight2
.VoidLink, an AI-assisted cloud-native malware framework identified in January 2026, provides further evidence that generative AI is making sophisticated malware development more accessible
1
. Kaspersky also highlighted ChatGPhish, an indirect prompt injection technique that hides malicious instructions inside webpages. When users ask an AI assistant to summarize such content, the AI can unknowingly relay malicious instructions or links1
.Kaspersky recommended that companies deploy AI-driven threat hunting, Zero Trust architecture, comprehensive protection across endpoints and networks, and AI-based detection and response to counter increasingly automated attacks
1
. "As attackers can leverage AI to automate decision-making and accelerate every stage of an attack, defenders must respond with the same level of intelligence," Ye Jin stated1
.The SilverFox campaign employs a multi-stage approach to payload delivery and utilizes segmented infrastructure, using different addresses and domains for various attack stages. These techniques minimize detection risk and prevent blocking of the entire attack chain
2
. Organizations must recognize that cyberattacks are evolving from specialized team operations to low-cost solo raids enabled by AI capabilities, fundamentally changing the threat landscape they face.Summarized by
Navi
14 Aug 2026•Technology
18 Mar 2026•Technology
13 Nov 2025•Technology

1
Technology

2
Technology

3
Policy and Regulation
