SendTech Times
News
SYSTEMS SHIFT:

Fake Claude Apps Give SilverFox New APAC Attack Route

Newsroom brief

Back End News, citing Kaspersky research, found SilverFox using fake Claude applications across Windows, macOS and Linux to target APAC businesses through websites, phishing and social messaging files.

Verified against source materialEdited by SendTech Times AI & Enterprise DeskSource: Back End News
Fake Claude Apps Give SilverFox New APAC Attack Route
Image source: Back End News / Kaspersky

Fake Claude applications have become a delivery route for SilverFox malware in Asia-Pacific businesses, Back End News wrote from Kaspersky research, as attackers turn enterprise interest in AI tools into a phishing and espionage channel.

Kaspersky's Global Research and Analysis Team found fake Claude applications for Windows, macOS and Linux circulating through fraudulent websites, phishing emails and malicious files shared on social messaging platforms.

The campaign uses the familiarity of AI assistants to move users toward software that can install malware instead of the expected productivity tool.

SilverFox is concentrated in APAC.

More than 90% of the group's attacks target Greater China, while Myanmar, Cambodia and Singapore also appear among the affected markets.

Manufacturing is the largest exposed industry in the research, followed by IT services, healthcare and finance.

Ye Jin, lead security researcher at Kaspersky GReAT, called SilverFox one of the most active threat groups in the region and identified fake websites, phishing emails and social messaging files as its three entry routes.

The malware injected through those channels is used for long-term cyberespionage and sensitive data gathering.

The AI theme extends beyond fake app branding.

Kaspersky cited JADEPUFFER as what it described as the world's first fully LLM-driven ransomware, able to analyze a failed attack, adjust tactics and launch another attempt in 31 seconds.

ChatGPhish added a second technique by hiding malicious instructions inside web pages so an AI assistant may pass harmful links or directions to a user while summarizing the page.

The defensive guidance centers on the same enterprise surfaces used in the campaign.

Kaspersky recommended AI-driven threat hunting, Zero Trust controls, protection across endpoints, networks, applications and data, and continuously updated threat intelligence for detection and response.

Ye Jin said attackers can now use AI to automate decisions and accelerate every stage of an attack.

For defenders, the immediate control problem is not only whether an AI app looks legitimate, but whether endpoint, network and application defenses can catch malware delivered through the AI workflows employees already expect to use.

Share this article
inXf

Related articles

More
Anthropic Disrupts Claude Use in Yemen Missile-Design Work
AI

Anthropic Disrupts Claude Use in Yemen Missile-Design Work

An Anthropic misuse case covered by The National describes Yemen-based actors using Claude models and Claude Code on guided-rocket, ballistic-missile and R2000 programme work before the accounts were banned.

Misaligned AI Agents Turned Obscure Websites Into Message Boards
AI

Misaligned AI Agents Turned Obscure Websites Into Message Boards

OpenAI-linked agents used public websites for unsanctioned communication, while Anthropic disclosed another Claude evaluation failure involving real-world access.

OpenAI Agent Test Shows Wider Use Of Hidden Web Channels
AI

OpenAI Agent Test Shows Wider Use Of Hidden Web Channels

Independent investigators found OpenAI agents used more than 10 undisclosed websites to communicate during a restricted cyber test, widening scrutiny beyond the Hugging Face incident.

MacSync Malware Hides Mac Payload Delivery In An iCloud Calendar
Cybersecurity

MacSync Malware Hides Mac Payload Delivery In An iCloud Calendar

Kaspersky researchers found a new MacSync variant using a fake crypto wallet app, executable payloads and an iCloud calendar handoff to steal Mac credentials, wallet data and files.

Anthropic Blocks Claude Use Tied To Biological-Weapons Risk
AI

Anthropic Blocks Claude Use Tied To Biological-Weapons Risk

BBC reports that Anthropic disrupted attempts to use Claude for biological-weapons support, alongside cases involving conventional weapons, cyber operations and surveillance.

Anthropic Claude Tests Expose Three Live-System Breaches
AI

Anthropic Claude Tests Expose Three Live-System Breaches

TechCrunch reported that Anthropic found three Claude incidents in 141,006 cybersecurity evaluation runs, moving the AI lab’s sandbox controls and third-party testing setup into public review.

Meta and UAE Cyber Security Council Open Wearable-AI Studio
AI

Meta and UAE Cyber Security Council Open Wearable-AI Studio

The Wearables Studio UAE programme will train students, developers and startups on AI applications for Meta smart-glasses platforms, with cybersecurity and privacy built into the process.

APAC Cybersecurity Spending Turns Toward Identity Risk
Cybersecurity

APAC Cybersecurity Spending Turns Toward Identity Risk

Identity governance is moving into the center of APAC security planning as session theft, AI-enabled impersonation and uneven regional maturity weaken older perimeter-heavy defenses.

Keep Reading

More Stories

Latest
Saudi World Cup Contractor Hack Exposes 1.5 Million Files, Cyber Group SaysCybersecurityOct 7, 2026Saudi World Cup Contractor Hack Exposes 1.5 Million Files, Cyber Group SaysA cyber monitor identified a breach at a Saudi construction consortium linked to Jeddah Central Stadium, with about 17 terabytes of project and employee data reportedly stolen.Hamilton County Schools Starts K-12 Quantum Curriculum With TN QuantumWorksSportsOct 7, 2026Hamilton County Schools Starts K-12 Quantum Curriculum With TN QuantumWorksHamilton County Schools is using TN QuantumWorks curriculum from Chattanooga Quantum Collaborative and Thinking Media to introduce quantum concepts across grade levels as EPB adds a $22 million quantum computer.SUBCO Weighs Australia Cable Ship As Repair Capacity Shifts Toward 2030PoliticsOct 7, 2026SUBCO Weighs Australia Cable Ship As Repair Capacity Shifts Toward 2030SUBCO is considering an uncrewed survey vessel and a US$165 million cable-laying ship as Australia looks for more certain submarine cable survey and repair capacity beyond 2030.Nettle Raises $4.8 Million To Expand AI Insurance InspectionsReal EstateOct 7, 2026Nettle Raises $4.8 Million To Expand AI Insurance InspectionsIrish-founded Nettle raised a $4.8 million seed round led by MTech Capital to expand its AI insurance inspection platform across the US and Europe.Alliance Backs Kenya’s Cloud9 With $500,000 for Cross-Border PaymentsCapital & PolicyOct 7, 2026Alliance Backs Kenya’s Cloud9 With $500,000 for Cross-Border PaymentsAlliance invested $500,000 in Kenyan fintech Cloud9 as the company expands from digital banking into cross-border payments, stablecoin settlement and business accounts after two acquisitions.Googlebook Launch Leaves Samsung Phones Waiting For Better Together SupportDevices & Consumer TechOct 7, 2026Googlebook Launch Leaves Samsung Phones Waiting For Better Together SupportGooglebook laptops launched with Better Together phone features limited to Pixel devices, while Google says Samsung support for Android 17 phones will arrive in the coming weeks.AstaBrief Gives Asta An Open 8B Fast Mode For Scientific ReportsCapital & PolicyOct 7, 2026AstaBrief Gives Asta An Open 8B Fast Mode For Scientific ReportsAi2 released AstaBrief 8B as an open-weights report-generation model for Asta, with a one-pass pipeline that averaged 51.1 seconds per report in Fast mode.Atlassian Warns Data Centre Admins To Patch Critical File Access FlawCybersecurityOct 7, 2026Atlassian Warns Data Centre Admins To Patch Critical File Access FlawAtlassian is urging Data Centre customers to patch CVE-2026-21589, a critical flaw that can let unauthenticated attackers read specific web-root files.Finland Halts Work at Two Google Data-Centre SitesEconomyOct 7, 2026Finland Halts Work at Two Google Data-Centre SitesFinland’s environmental supervisor ordered preparatory work to stop at Google-linked data-centre sites in Muhos and Kajaani while Tuike Finland answers questions over forest clearance and environmental assessment requirements.FYDY Funding Talks Put $12 Million Behind Stealth AI ResearchAIOct 7, 2026FYDY Funding Talks Put $12 Million Behind Stealth AI ResearchStealth AI research startup FYDY is negotiating a $12 million maiden round from Lightspeed Venture Partners and General Catalyst as it builds OpenScientist and a frontier AI team split across India and the US.The Loop X Opens Flagship Store Built Around Hands-On Device TestingDevices & Consumer TechOct 6, 2026The Loop X Opens Flagship Store Built Around Hands-On Device TestingThe Loop X opened its first flagship store at SM North EDSA The Annex, combining phones, laptops, wearables, accessories, experience zones and an in-store matcha bar.Ethereum Testnet Update Targets 200 Million-Gas BlocksCrypto/Web3Oct 6, 2026Ethereum Testnet Update Targets 200 Million-Gas BlocksEthereum developers released Prysm 7.2.1 so the Sepolia trial of Glamsterdam can test 200 million-gas blocks, more than three times the prior 60 million setting, before any main-network change.