Kaspersky GReAT: SilverFox Targets APAC With Fake Claude Malware
August 27, 2026: Kaspersky GReAT researchers have identified SilverFox as one of the most active threat groups in APAC. The group uses fake websites, phishing emails and malicious files shared through social messaging apps to deploy malware for long-term cyberespionage and sensitive data theft. Its latest tactic involves distributing fake Claude applications for Windows, macOS and Linux, exploiting the growing use of AI tools in organisations.
“SilverFox is one of the most active threat groups in the whole APAC region. They get into targets through three simple routes: fake websites, phishing emails, and harmful files spread via social messaging apps. They inject malware used for long-term cyberespionage and sensitive data gathering. Our recent analysis showed they are now distributing fake Claude for Windows, macOS, and Linux, leveraging AI use in companies to crack into their targets’ security defenses,” explains Ye Jin (Seth), lead security researcher at Kaspersky GReAT.
Greater China remains SilverFox’s primary target, accounting for more than 90% of attacks, with mainland China alone representing 71%. Myanmar, Cambodia and Singapore are also emerging hotspots. Manufacturing is the group’s most targeted industry, followed by IT and services, healthcare and finance.
“Based on our current threat data, Greater China is SilverFox’s main target with over 90% of all its attacks targeting the region. Mainland China alone makes up 71%. Myanmar, Cambodia and Singapore also see lots of attacks. These are the next hotspots we need to watch,” adds Ye Jin.
Kaspersky also highlighted the growing threat from agentic AI, including JADEPUFFER, described as the world’s first fully LLM-driven ransomware. The malicious AI agent reportedly diagnosed a failed attack, corrected its approach and launched a new attack in just 31 seconds, demonstrating unprecedented speed and autonomy.
“In this particular case, disclosed by our Sysdig, the malicious AI agent completed the entire cycle of diagnosing a failed attempt, correcting its approach, and launching a new attack in just 31 seconds, far outpacing the response capabilities of most human defenders. Beyond speed, JADEPUFFER also demonstrates an unprecedented level of autonomy. It shows that AI agents are now capable of making independent decisions throughout the attack process, effectively replicating the reasoning of an experienced human attacker without direct oversight,” he explains.
Kaspersky recommends proactive AI-driven threat hunting, Zero Trust architecture, systematic protection across the technology environment, and using AI to strengthen detection and response.
“When attackers can leverage AI to automate decision-making and accelerate every stage of an attack, defenders must respond with the same level of intelligence. Cybersecurity solutions enriched with continuously updated threat intelligence are no longer a competitive advantage, but a critical requirement for staying ahead of rapidly evolving threats,” adds Ye Jin.