{"id":142638,"date":"2026-08-17T17:51:12","date_gmt":"2026-08-17T17:51:12","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/142638\/"},"modified":"2026-08-17T17:51:12","modified_gmt":"2026-08-17T17:51:12","slug":"how-silverfox-cybercriminal-group-is-using-claude-to-target-companies-in-india-and-other-asian-countries","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/142638\/","title":{"rendered":"How Silverfox cybercriminal group is using Claude to target companies in India and other Asian countries"},"content":{"rendered":"<p> <img src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/silverfox-cybercrime-group-targetting-indian-companies-with-fake-claude-ai-apps-heres-how.jpg\" alt=\"How Silverfox cybercriminal group is using Claude to target companies in India and other Asian countries\" title=\"Representative Image\" decoding=\"async\" fetchpriority=\"high\"\/> \u200bSilverFox, an Advanced Persistent Threat (APT) group, is using fake Claude apps to target companies in India and other countries in the Asia Pacific region. According to researchers from Kaspersky\u2019s Global Research and Analysis Team (GReAT), the cybercriminal group is exploiting the growing use of artificial intelligence (AI) tools in businesses to distribute malware and gain access to target networks.\u200b\u201cSilverFox is one of the most active threat groups in the whole APAC region. They get into targets through three simple routes: fake websites, phishing emails, and harmful files spread via social messaging apps. They inject malware used for long-term cyberespionage and sensitive data gathering. Our recent analysis showed they are now distributing fake Claude for Windows, macOS, and Linux, leveraging AI use in companies to crack into their targets\u2019 security defenses,\u201d explains Ye Jin (Seth), Lead Security Researcher at Kaspersky GReAT.\u200b<\/p>\n<p>How SilverFox uses fake Claude apps to target companies<\/p>\n<p>\u200bKaspersky researchers said SilverFox has used a multi-stage attack process and segmented infrastructure, with different addresses and domains used at different stages. The approach can make it harder for security teams to identify and block the complete attack chain.\u200bThe group\u2019s recent campaign targeted organisations in India, Indonesia, South Africa and Russia across industrial, consulting, trade and transportation sectors. Attackers sent phishing emails designed to appear like official tax audit notifications or messages asking recipients to download an archive containing a supposed \u201clist of tax violations.\u201d\u200bMore than 1,600 malicious emails were detected in January-February 2026, according to Kaspersky data. The emails often used a sense of authority and urgency, similar to messages about taxes, to trick people into opening malicious files and launching the attacks.\u200bMore recent findings indicate that SilverFox has expanded its tactics to fake versions of Claude for Windows, macOS and Linux. Claude is an AI assistant developed by Anthropic that can be used for writing, coding, analysing documents and other tasks.\u200b<\/p>\n<p>SilverFox attacks remain concentrated in Asia<\/p>\n<p>\u200bKaspersky said the APAC region accounts for the largest share of SilverFox\u2019s malicious activity, with attack volumes exceeding those recorded across other regions combined.\u200b\u201cBased on our current threat data, Greater China is SilverFox\u2019s main target, with over 90% of all its attacks targeting the region. Mainland China alone makes up 71%. Myanmar, Cambodia and Singapore also see lots of attacks. These are the next hotspots we need to watch,\u201d adds Ye Jin.\u200bManufacturing accounts for more than one-third of the group\u2019s attacks, making it the most targeted industry in Kaspersky\u2019s current data. IT and services are also frequently targeted, while healthcare and finance remain among the sectors facing attacks from the group.\u200b<\/p>\n<p>AI is changing the speed and scale of cyberattacks<\/p>\n<p>\u200bKaspersky\u2019s Ye Jin also highlighted the emergence of AI-driven attacks that can automate decisions and parts of the attack process. One example is JADEPUFFER, described as an LLM-driven ransomware attack that demonstrated how an AI agent could analyse a failed attempt, change its approach and launch another attack.\u200b\u201cIn this particular case, disclosed by our Sysdig, the malicious AI agent completed the entire cycle of diagnosing a failed attempt, correcting its approach, and launching a new attack in just 31 seconds, far outpacing the response capabilities of most human defenders. Beyond speed, JADEPUFFER also demonstrates an unprecedented level of autonomy. It shows that AI agents are now capable of making independent decisions throughout the attack process, effectively replicating the reasoning of an experienced human attacker without direct oversight,\u201d he explains.\u200bAnother example highlighted by the researcher is ChatGPhish, an indirect prompt injection technique in which malicious instructions are hidden inside webpages. When a user asks an AI assistant to summarise such a page, the embedded instructions can potentially be processed by the AI and surfaced as part of its response.\u200bKaspersky also pointed to VoidLink, an AI-assisted cloud-native malware framework reported in January 2026, as an example of how generative AI can reduce the technical effort required to develop malware.\u200b<\/p>\n<p>How companies can defend against AI-powered attacks<\/p>\n<p>\u200bKaspersky recommends that organisations adapt their security measures as attackers increasingly use AI and automated techniques. Its suggested measures include proactive AI-driven threat hunting to identify unknown threats, alongside Zero Trust architecture that verifies access requests rather than automatically trusting users or devices inside a network.\u200bThe company also recommends a systematic defence covering endpoints, networks, applications and data. Another approach is using AI models and other dual-use AI technologies to improve threat detection and response and adapt security measures as attack techniques change.\u200bThe growing use of AI by both attackers and defenders means organisations need to account for AI-assisted phishing, malware distribution and automated attack processes alongside conventional cybersecurity threats.<\/p>\n","protected":false},"excerpt":{"rendered":"\u200bSilverFox, an Advanced Persistent Threat (APT) group, is using fake Claude apps to target companies in India and&hellip;\n","protected":false},"author":2,"featured_media":142639,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[12409,70301,53,3154,182,70300,70302,70303,70304,70305,70299,53780],"class_list":["post-142638","post","type-post","status-publish","format-standard","has-post-thumbnail","category-anthropic","tag-ai-in-cybersecurity","tag-ai-driven-cyberattacks","tag-anthropic","tag-anthropic-claude","tag-claude","tag-claude-fake-apps","tag-cybersecurity-threats-in-asia","tag-malware-distribution-techniques","tag-phishing-emails-attacks","tag-silverfox","tag-silverfox-cybercriminal-group","tag-zero-trust-architecture"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/142638","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=142638"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/142638\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/142639"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=142638"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=142638"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=142638"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}