SilverFox, an Advanced Persistent Threat (APT) group, is using fake Claude apps to target companies in India and other countries in the Asia Pacific region. According to researchers from Kaspersky’s Global Research and Analysis Team (GReAT), the cybercriminal group is exploiting the growing use of artificial intelligence (AI) tools in businesses to distribute malware and gain access to target networks.“SilverFox is one of the most active threat groups in the whole APAC region. They get into targets through three simple routes: fake websites, phishing emails, and harmful files spread via social messaging apps. They inject malware used for long-term cyberespionage and sensitive data gathering. Our recent analysis showed they are now distributing fake Claude for Windows, macOS, and Linux, leveraging AI use in companies to crack into their targets’ security defenses,” explains Ye Jin (Seth), Lead Security Researcher at Kaspersky GReAT.
How SilverFox uses fake Claude apps to target companies
Kaspersky researchers said SilverFox has used a multi-stage attack process and segmented infrastructure, with different addresses and domains used at different stages. The approach can make it harder for security teams to identify and block the complete attack chain.The group’s recent campaign targeted organisations in India, Indonesia, South Africa and Russia across industrial, consulting, trade and transportation sectors. Attackers sent phishing emails designed to appear like official tax audit notifications or messages asking recipients to download an archive containing a supposed “list of tax violations.”More than 1,600 malicious emails were detected in January-February 2026, according to Kaspersky data. The emails often used a sense of authority and urgency, similar to messages about taxes, to trick people into opening malicious files and launching the attacks.More recent findings indicate that SilverFox has expanded its tactics to fake versions of Claude for Windows, macOS and Linux. Claude is an AI assistant developed by Anthropic that can be used for writing, coding, analysing documents and other tasks.
SilverFox attacks remain concentrated in Asia
Kaspersky said the APAC region accounts for the largest share of SilverFox’s malicious activity, with attack volumes exceeding those recorded across other regions combined.“Based on our current threat data, Greater China is SilverFox’s main target, with over 90% of all its attacks targeting the region. Mainland China alone makes up 71%. Myanmar, Cambodia and Singapore also see lots of attacks. These are the next hotspots we need to watch,” adds Ye Jin.Manufacturing accounts for more than one-third of the group’s attacks, making it the most targeted industry in Kaspersky’s current data. IT and services are also frequently targeted, while healthcare and finance remain among the sectors facing attacks from the group.
AI is changing the speed and scale of cyberattacks
Kaspersky’s Ye Jin also highlighted the emergence of AI-driven attacks that can automate decisions and parts of the attack process. One example is JADEPUFFER, described as an LLM-driven ransomware attack that demonstrated how an AI agent could analyse a failed attempt, change its approach and launch another attack.“In this particular case, disclosed by our Sysdig, the malicious AI agent completed the entire cycle of diagnosing a failed attempt, correcting its approach, and launching a new attack in just 31 seconds, far outpacing the response capabilities of most human defenders. Beyond speed, JADEPUFFER also demonstrates an unprecedented level of autonomy. It shows that AI agents are now capable of making independent decisions throughout the attack process, effectively replicating the reasoning of an experienced human attacker without direct oversight,” he explains.Another example highlighted by the researcher is ChatGPhish, an indirect prompt injection technique in which malicious instructions are hidden inside webpages. When a user asks an AI assistant to summarise such a page, the embedded instructions can potentially be processed by the AI and surfaced as part of its response.Kaspersky also pointed to VoidLink, an AI-assisted cloud-native malware framework reported in January 2026, as an example of how generative AI can reduce the technical effort required to develop malware.
How companies can defend against AI-powered attacks
Kaspersky recommends that organisations adapt their security measures as attackers increasingly use AI and automated techniques. Its suggested measures include proactive AI-driven threat hunting to identify unknown threats, alongside Zero Trust architecture that verifies access requests rather than automatically trusting users or devices inside a network.The company also recommends a systematic defence covering endpoints, networks, applications and data. Another approach is using AI models and other dual-use AI technologies to improve threat detection and response and adapt security measures as attack techniques change.The growing use of AI by both attackers and defenders means organisations need to account for AI-assisted phishing, malware distribution and automated attack processes alongside conventional cybersecurity threats.