2 Sources
[1]
SilverFox hackers use fake Claude apps to target companies in Asia: Kaspersky
Cybersecurity group SilverFox is exploiting artificial intelligence across Asia Pacific. They distribute fake Claude AI applications for various operating systems. Kaspersky researchers identified SilverFox as a highly active threat group in the region. This group targets manufacturing, IT,
[2]
Kaspersky GReAT: Top APT Group Targets APAC with Malware via Fake Claude App
Researcher from Kaspersky's Global Research and Analysis Team (GReAT) gave the lowdown on how SilverFox - one of the most active Advanced Persistent Threat (APT) groups - piggybacks on the rising Artificial Intelligence (AI) use in industries in Asia Pacific (APT). He also warns that fast-evolving
Share
Copy Link
Kaspersky researchers uncovered SilverFox, one of Asia Pacific's most active advanced persistent threat groups, distributing fake Claude AI applications for Windows, macOS, and Linux to infiltrate organizations. The campaign primarily targets Greater China, accounting for over 90% of attacks, with manufacturing, IT services, healthcare, and finance sectors most at risk.

Kaspersky's Global Research and Analysis Team (GReAT) identified SilverFox as one of the most active advanced persistent threat groups operating in Asia Pacific, exploiting the growing adoption of artificial intelligence in businesses. First detected in December 2025, SilverFox has rapidly escalated its operations by distributing fake Claude apps across Windows, macOS, and Linux platforms to target companies in Asia
1
. The group infiltrates organizations through three primary vectors: fake websites, phishing emails, and malicious files distributed via social messaging apps2
.Ye Jin (Seth), Lead Security Researcher at Kaspersky GReAT, emphasized the group's sophistication: "They inject malware used for long-term cyberespionage and sensitive data gathering. Our recent analysis showed they are now distributing fake Claude for Windows, macOS, and Linux, leveraging AI use in companies to crack into their targets' security defenses"
2
. This exploitation of AI-themed lures represents a calculated shift in social engineering tactics, capitalizing on organizations' rush to adopt AI tools.The geographic concentration of SilverFox operations reveals a clear pattern. Greater China represents more than 90% of all attacks, with mainland China alone accounting for 71% of malicious activity
1
. Myanmar, Cambodia, and Singapore have emerged as the next hotspots requiring heightened vigilance2
. Recent campaigns extended beyond Asia, targeting companies in India, Indonesia, South Africa, and Russia across industrial, consulting, trade, and transportation sectors1
.The Asia Pacific region experiences a volume of SilverFox activity far exceeding all other regions combined, indicating the group's concentrated focus on East and Southeast Asian targets
2
. This geographic targeting suggests either regional infrastructure vulnerabilities or specific intelligence objectives driving the campaign.Manufacturing makes up more than one-third of all SilverFox attacks, establishing it as the top target industry
2
. IT services follow closely behind, with researchers observing substantial phishing aimed at tech workers2
. Healthcare and finance sectors also face significant risks from this group known for pursuing high-value targets1
.In one documented campaign, attackers sent phishing emails disguised as official tax audit notifications, prompting recipients to download an archive purportedly containing a "list of tax violations." Kaspersky recorded more than 1,600 malicious emails between January and February 2026
1
. This tactic leverages the perceived authority and urgency of communications from tax agencies to persuade victims to trigger the attack chain2
.Related Stories
Kaspersky researchers warned that artificial intelligence is fundamentally lowering the cost and technical expertise required to launch sophisticated cyberattacks
1
. The emergence of JADEPUFFER, described as the world's first fully LLM-driven ransomware, marked a significant turning point in cyber threats. Unlike previous attacks where AI merely augmented human operators, JADEPUFFER demonstrated AI acting as both decision-maker and executor2
.In a case disclosed by Sysdig, a malicious AI agent completed the entire cycle of diagnosing a failed attempt, correcting its approach, and launching a new attack in just 31 seconds
1
. This speed far outpaces the response capabilities of most human defenders, demonstrating an unprecedented level of autonomy where AI agents replicate the reasoning of experienced attackers without direct oversight2
.VoidLink, an AI-assisted cloud-native malware framework identified in January 2026, provides further evidence that generative AI is making sophisticated malware development more accessible
1
. Kaspersky also highlighted ChatGPhish, an indirect prompt injection technique that hides malicious instructions inside webpages. When users ask an AI assistant to summarize such content, the AI can unknowingly relay malicious instructions or links1
.Kaspersky recommended that companies deploy AI-driven threat hunting, Zero Trust architecture, comprehensive protection across endpoints and networks, and AI-based detection and response to counter increasingly automated attacks
1
. "As attackers can leverage AI to automate decision-making and accelerate every stage of an attack, defenders must respond with the same level of intelligence," Ye Jin stated1
.The SilverFox campaign employs a multi-stage approach to payload delivery and utilizes segmented infrastructure, using different addresses and domains for various attack stages. These techniques minimize detection risk and prevent blocking of the entire attack chain
2
. Organizations must recognize that cyberattacks are evolving from specialized team operations to low-cost solo raids enabled by AI capabilities, fundamentally changing the threat landscape they face.Summarized by
Navi
14 Aug 2026•Technology
18 Mar 2026•Technology
13 Nov 2025•Technology

1
Technology

2
Technology

3
Science and Research
