SilverFox APT Group Spreads Malware via Fake Claude Apps

Kaspersky’s Global Research and Analysis Team (GReAT) has uncovered a campaign by SilverFox, one of the most active Advanced Persistent Threat (APT) groups in Asia Pacific, distributing fake Claude applications to infiltrate target organisations. The threat actor is exploiting the rising enterprise adoption of AI tools, with Mainland China and Singapore among its key targets.

SilverFox, first detected by Kaspersky GReAT in December 2025, employs a multi-stage payload delivery approach using segmented infrastructure to minimise detection risk. Its latest campaign distributes fake versions of Claude, the AI assistant developed by Anthropic, for Windows, macOS and Linux.

“SilverFox is one of the most active threat groups in the whole APAC region. They get into targets through three simple routes: fake websites, phishing emails, and harmful files spread via social messaging apps. They inject malware used for long-term cyberespionage and sensitive data gathering. Our recent analysis showed they are now distributing fake Claude for Windows, macOS, and Linux, leveraging AI use in companies to crack into their targets’ security defenses,” said Ye Jin (Seth), Lead Security Researcher, Kaspersky GReAT.

Greater China and Southeast Asia Bear the Brunt

Kaspersky’s threat data shows Greater China accounts for over 90% of SilverFox’s attacks, with Mainland China alone making up 71%. Myanmar, Cambodia and Singapore are flagged as emerging hotspots. Manufacturing is the top target industry, accounting for more than a third of all attacks, followed by IT and services, healthcare and finance.

  • Greater China: over 90% of all SilverFox attacks
  • Mainland China alone: 71% of attacks
  • Manufacturing: more than one-third of targeted attacks
  • Emerging hotspots: Myanmar, Cambodia, Singapore

“Based on our current threat data, Greater China is SilverFox’s main target with over 90% of all its attacks targeting the region. Mainland China alone makes up 71%. Myanmar, Cambodia and Singapore also see lots of attacks. These are the next hotspots we need to watch,” added Ye Jin.

Agentic AI Is Reshaping the Threat Landscape

GReAT researchers also detailed JADEPUFFER, described as the world’s first fully LLM-driven ransomware, which acted as both decision-maker and executor in an attack rather than merely augmenting a human operator. In one case disclosed by Sysdig, the malicious AI agent diagnosed a failed attempt, corrected its approach and launched a new attack within 31 seconds.

Kaspersky also flagged ChatGPhish, an indirect prompt injection technique that hides malicious instructions inside webpages to trick AI web-summarisation tools into relaying harmful links, and VoidLink, an AI and cloud-native malware framework developed almost entirely with generative AI assistance.

Kaspersky recommends four countermeasures for enterprises: proactive AI-driven threat hunting, Zero Trust architecture, a comprehensive defence system spanning endpoints, networks, applications and data, and using AI-enhanced detection to match the speed of AI-driven attackers.

“When attackers can leverage AI to automate decision-making and accelerate every stage of an attack, defenders must respond with the same level of intelligence. Cybersecurity solutions enriched with continuously updated threat intelligence are no longer a competitive advantage, but a critical requirement for staying ahead of rapidly evolving threats,” said Ye Jin.

Author


Discover more from techcoffeehouse.com

Subscribe to get the latest posts sent to your email.

Use promo code “TCH15” to get 15% off on checkout.

Share your thoughts

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading