Monday, August 10, 2026

Cyberespionage group using fake AI apps to expand attacks across Asia-Pacific

Cyberespionage group SilverFox is using counterfeit artificial intelligence applications and phishing campaigns to target businesses across the Asia-Pacific region, according to researchers from Kaspersky’s Global Research and Analysis Team (GReAT).

During Kaspersky’s Cyber Security Weekend in China, researchers said the group has taken advantage of growing corporate reliance on AI tools by distributing fake versions of Anthropic’s Claude assistant for Windows, macOS, and Linux. The counterfeit applications are designed to install malware and gain access to company systems.

“SilverFox is one of the most active threat groups in the whole APAC region. They inject malware used for long-term cyberespionage and sensitive data gathering,” Kaspersky GReAT senior security researcher Ye Jin (Seth) said.

Kaspersky said it identified SilverFox in December 2025 and linked the group to attacks that use multi-stage payload delivery and segmented infrastructure spread across multiple addresses and domains. These methods make the campaigns harder to detect and disrupt.

Recent targets included companies in India, Indonesia, South Africa, and Russia, particularly those operating in the industrial, consulting, trade, and transportation sectors.

The attackers sent phishing emails disguised as official tax audit notices or messages offering archives supposedly containing “lists of tax violations.” Kaspersky recorded more than 1,600 of these malicious emails from January to February 2026.

The Asia-Pacific region accounted for most of the group’s activity, with Greater China representing 90% of detected attacks. Mainland China alone accounted for 71%, while Myanmar, Cambodia, and Singapore were identified as emerging targets.

Manufacturing was the most frequently targeted industry, followed by IT services, healthcare, and finance.

Kaspersky researchers also pointed to the emergence of JADEPUFFER, which they described as the first ransomware capable of carrying out attacks through a fully AI-driven process.

Unlike conventional ransomware operations that depend on human operators for key decisions, the malware can reportedly assess failed attempts and initiate another attack within 31 seconds.

Researchers said the growing use of agentic AI could allow attacks to be carried out more quickly and with less direct human involvement.

Another emerging technique, dubbed “ChatGPhish,” uses malicious prompt injections delivered through trusted AI tools. This could make attacks more difficult to identify because the malicious activity is routed through platforms that employees and organizations already use.

- Advertisement -spot_img

RELEVANT STORIES

spot_img

LATEST

- Advertisement -spot_img