Fake Claude Apps Give SilverFox New APAC Attack Route
Back End News, citing Kaspersky research, found SilverFox using fake Claude applications across Windows, macOS and Linux to target APAC businesses through websites, phishing and social messaging files.

Fake Claude applications have become a delivery route for SilverFox malware in Asia-Pacific businesses, Back End News wrote from Kaspersky research, as attackers turn enterprise interest in AI tools into a phishing and espionage channel.
Kaspersky's Global Research and Analysis Team found fake Claude applications for Windows, macOS and Linux circulating through fraudulent websites, phishing emails and malicious files shared on social messaging platforms.
The campaign uses the familiarity of AI assistants to move users toward software that can install malware instead of the expected productivity tool.
SilverFox is concentrated in APAC.
More than 90% of the group's attacks target Greater China, while Myanmar, Cambodia and Singapore also appear among the affected markets.
Manufacturing is the largest exposed industry in the research, followed by IT services, healthcare and finance.
Ye Jin, lead security researcher at Kaspersky GReAT, called SilverFox one of the most active threat groups in the region and identified fake websites, phishing emails and social messaging files as its three entry routes.
The malware injected through those channels is used for long-term cyberespionage and sensitive data gathering.
The AI theme extends beyond fake app branding.
Kaspersky cited JADEPUFFER as what it described as the world's first fully LLM-driven ransomware, able to analyze a failed attack, adjust tactics and launch another attempt in 31 seconds.
ChatGPhish added a second technique by hiding malicious instructions inside web pages so an AI assistant may pass harmful links or directions to a user while summarizing the page.
The defensive guidance centers on the same enterprise surfaces used in the campaign.
Kaspersky recommended AI-driven threat hunting, Zero Trust controls, protection across endpoints, networks, applications and data, and continuously updated threat intelligence for detection and response.
Ye Jin said attackers can now use AI to automate decisions and accelerate every stage of an attack.
For defenders, the immediate control problem is not only whether an AI app looks legitimate, but whether endpoint, network and application defenses can catch malware delivered through the AI workflows employees already expect to use.




















