Fake AI Apps Emerge as Cyber Weapon as SilverFox Targets APAC Organizations

Fake AI Apps Emerge as Cyber Weapon as SilverFox Targets APAC Organizations
Fake AI Apps Emerge as Cyber Weapon as SilverFox Targets APAC Organizations

As organizations across the Asia Pacific region rapidly adopt artificial intelligence, cybercriminals are increasingly using the popularity of AI tools to target businesses. New research from Kaspersky’s Global Research and Analysis Team (GReAT) shows that the advanced persistent threat (APT) group SilverFox is using fake AI applications, including counterfeit versions of Anthropic’s Claude assistant, as part of cyberespionage campaigns.

Kaspersky researchers identify SilverFox as one of the most active threat groups operating in the APAC region. The group's recent activity demonstrates how attackers are adapting their techniques to take advantage of growing enterprise reliance on AI technologies.

Kaspersky first identified SilverFox in December 2025. Since then, the group has been associated with multi-stage attack chains and segmented infrastructure intended to make its operations more difficult to detect. Its campaigns have used fake websites, phishing emails and malicious files distributed through social messaging platforms to compromise targets and deploy malware for surveillance and data theft.

“SilverFox is one of the most active threat groups in the APAC region. They are now distributing fake Claude applications for Windows, macOS and Linux, leveraging the growing use of AI inside organizations to bypass security defenses and conduct long-term cyberespionage and data theft,” said Ye Jin (Seth), Lead Security Researcher at Kaspersky GReAT.

SilverFox Uses Fake AI Applications to Target Businesses

One of SilverFox's recent campaigns targeted organizations in India, Indonesia, South Africa and Russia, covering sectors such as manufacturing, consulting, transportation and trade.

The attackers used phishing emails designed to resemble official tax audit notifications. The messages contained files presented as lists of tax violations, using the urgency and perceived authority associated with government communications to encourage recipients to open the malicious files.

Kaspersky recorded more than 1,600 malicious emails linked to this activity during January and February 2026.

Fake Claude Applications Target Windows, macOS and Linux

SilverFox has also adopted a tactic involving counterfeit versions of Claude, Anthropic's AI assistant.

The fake applications are designed for Windows, macOS and Linux, taking advantage of the increasing use of generative AI tools within organizations. Claude is used for activities including content creation, coding, document analysis and business problem-solving.

By presenting malicious software as a legitimate AI application, attackers can attempt to convince employees to install the software on their devices. Kaspersky said the campaign demonstrates how cybercriminals are exploiting trusted AI brands as part of their efforts to gain access to enterprise environments.

Greater China Remains the Main Focus

Kaspersky's research indicates that more than 90% of SilverFox attacks target Greater China.

Mainland China accounts for approximately 71% of the group's observed activity, while researchers have also recorded significant activity in Myanmar, Cambodia and Singapore.

Manufacturing is the most targeted industry, representing more than one-third of the attacks. Technology and IT services organizations are also among the targeted sectors, followed by healthcare and financial institutions, which hold sensitive information and valuable assets.

AI-Powered Attacks Become More Autonomous

Kaspersky researchers also highlighted the wider development of AI-powered cyberattacks that can operate with greater speed and autonomy.

Ye Jin pointed to JADEPUFFER, which Kaspersky describes as the world's first fully large language model-driven ransomware. Unlike conventional ransomware operations that depend on human operators to guide different stages of an attack, JADEPUFFER demonstrated the ability to assess unsuccessful attempts, change its approach and launch another attack independently.

In one documented example, the AI agent evaluated a failed attack, adjusted its tactics and initiated another attempt within 31 seconds.

According to the researchers, such capabilities could reduce attackers' dependence on highly skilled human operators while allowing malicious activity to progress more rapidly.

AI Also Enables More Covert Attack Techniques

Kaspersky researchers identified ChatGPhish as another example of how AI-related technologies can be incorporated into attack techniques.

The technique involves indirect prompt injection targeting AI-powered web summarization tools. Malicious instructions can be embedded in webpages, with users then encouraged to ask an AI assistant to summarize the content. The AI system may subsequently present malicious links or instructions to the user.

Because the information is delivered through an AI interface that users may already trust, they could be more inclined to follow the recommendation. Kaspersky noted that conventional security solutions can face challenges detecting this type of activity because it can resemble normal interactions with AI tools.

AI is also lowering barriers to the development of sophisticated malware. Kaspersky cited VoidLink, an AI-developed cloud-native malware framework identified in early 2026, as an example of how generative AI can assist in the creation of advanced cyber threats.

Kaspersky Calls for AI-Driven Cybersecurity

With attackers increasingly incorporating AI into their operations, Kaspersky recommends that organizations strengthen their defensive capabilities through AI-driven threat hunting, Zero Trust security architectures, comprehensive endpoint and network protection, and AI-enhanced detection and response.

The company said organizations need to move beyond purely reactive cybersecurity approaches as AI enables attacks to become faster and more autonomous.

As artificial intelligence becomes increasingly integrated into business operations, the technology is also becoming a growing component of the cyber threat landscape. Kaspersky's findings highlight the need for organizations to strengthen security strategies alongside their continued adoption of AI.