Kaspersky researchers warn that one of the region’s most active threat groups is exploiting enterprise AI adoption, while AI-powered cyberattacks are becoming faster, more autonomous and harder to detect
As businesses across Asia Pacific accelerate the adoption of artificial intelligence, cybercriminals are increasingly turning that enthusiasm into a powerful attack vector. According to new research from Kaspersky’s Global Research and Analysis Team (GReAT), the advanced persistent threat (APT) group known as SilverFox is leveraging fake AI applications, including counterfeit versions of Anthropic’s Claude assistant, to infiltrate organizations and conduct cyberespionage operations.
Kaspersky researchers describe SilverFox as one of the most active threat actors currently operating in the APAC region. The group’s latest campaigns demonstrate how cybercriminals are adapting their tactics to exploit the rapid enterprise adoption of AI technologies.
Originally identified by Kaspersky in December 2025, SilverFox has built a reputation for using sophisticated, multi-stage attack chains and segmented infrastructure designed to avoid detection. The group relies on fake websites, phishing emails and malicious files distributed through social messaging platforms to compromise targets and deploy malware capable of long-term surveillance and data theft.
“SilverFox is one of the most active threat groups in the APAC region. They are now distributing fake Claude applications for Windows, macOS and Linux, leveraging the growing use of AI inside organizations to bypass security defenses and conduct long-term cyberespionage and data theft,” said Ye Jin (Seth), Lead Security Researcher at Kaspersky GReAT.
One of its most recent campaigns targeted organizations in India, Indonesia, South Africa and Russia across industries including manufacturing, consulting, transportation and trade. Attackers disguised phishing emails as official tax audit notifications and included files claiming to contain lists of tax violations. By exploiting urgency and perceived government authority, victims were encouraged to download the malicious files and unknowingly trigger the attack chain.
Kaspersky recorded more than 1,600 such malicious emails during January and February 2026 alone.
AI Adoption Creates a New Attack Opportunity
The latest findings reveal a notable shift in SilverFox’s tactics. The threat group is now distributing fake Claude applications for Windows, macOS and Linux platforms, capitalizing on the growing popularity of generative AI tools in corporate environments.
Claude, developed by Anthropic, is widely used for content creation, coding, document analysis and business problem-solving. By disguising malware as legitimate AI software, attackers increase the likelihood that employees will download and install the malicious applications.
According to Kaspersky, this strategy highlights how threat actors are increasingly exploiting trusted AI brands to bypass security awareness and gain access to enterprise networks.
Greater China Remains the Primary Target
The research also provides insight into SilverFox’s geographic focus.
More than 90 percent of the group’s attacks target Greater China, with mainland China accounting for approximately 71 percent of observed activity. Kaspersky researchers also identified significant attack volumes in Myanmar, Cambodia and Singapore.
The concentration of activity suggests that East and Southeast Asia remain the primary focus of SilverFox operations.
Industry analysis shows that manufacturing is the most targeted sector, accounting for more than one-third of all attacks. Technology and IT services organizations follow closely behind, with healthcare and financial institutions also facing elevated risks due to the sensitive information and high-value assets they manage.
The Rise of Autonomous AI Attacks
Beyond SilverFox, Kaspersky researchers highlighted a broader transformation underway in cybercrime: the emergence of AI-powered attacks capable of operating with unprecedented speed and autonomy.
Ye Jin pointed to JADEPUFFER, described as the world’s first fully large language model-driven ransomware. Unlike traditional ransomware campaigns where human operators guide attacks, JADEPUFFER demonstrated the ability to analyze failures, adjust tactics and relaunch attacks independently.
In one documented case, the AI agent reportedly assessed a failed attack attempt, modified its approach and executed a new attack within just 31 seconds.
Researchers believe this level of autonomy marks a significant shift in cyber threats, reducing reliance on skilled human operators while dramatically accelerating attack execution.
Increased Stealth and Accessibility
AI is also helping attackers operate more stealthily.
Kaspersky highlighted a technique known as ChatGPhish, an indirect prompt injection attack that targets AI-powered web summarization tools. Attackers embed hidden instructions within webpages and persuade victims to ask AI assistants to summarize the content. The AI system then unknowingly relays malicious links or instructions to the user.
Because the recommendation appears to come from a trusted AI interface, users may be more likely to follow harmful guidance. Traditional security tools often struggle to identify such attacks because the interaction resembles normal AI usage rather than conventional malicious activity.
The rise of AI-assisted malware development is lowering technical barriers as well. Kaspersky referenced VoidLink, an AI-developed cloud-native malware framework discovered in early 2026, as evidence that sophisticated cyber weapons can increasingly be created with extensive assistance from generative AI technologies.
Fighting AI with AI
As attackers embrace artificial intelligence, Kaspersky argues that defenders must do the same.
The company recommends a four-pronged approach: proactive AI-driven threat hunting, Zero Trust security architectures, comprehensive protection across endpoints and networks, and the deployment of AI-enhanced detection and response capabilities.
According to Kaspersky, cybersecurity teams can no longer rely solely on reactive defenses. As AI enables faster and more autonomous attacks, organizations must adopt AI-native security strategies capable of identifying, analyzing and responding to threats at machine speed.
The message from researchers is clear: as AI becomes embedded in business operations, it is simultaneously becoming one of the most powerful tools in the cybercriminal arsenal. Organizations that fail to adapt their defenses accordingly risk falling behind in an increasingly automated threat landscape.
