Researcher from Kaspersky’s Global Research and Analysis Team (GReAT) gave the lowdown on how SilverFox – one of the most active Advanced Persistent Threat (APT) groups – piggybacks on the rising Artificial Intelligence (AI) use in industries in Asia Pacific (APT). He also warns that fast-evolving Artificial Intelligence (AI) capabilities are ushering in an era where cyberattacks turn from “specialised team operations” to “low-cost solo raids”.
The threat actor, detected by Kaspersky Global Research and Analysis Team (GReAT) researchers back in December 2025, is known for employing a multi-stage approach to payload delivery and utilises a segmented infrastructure, using different addresses and domains for various stages of the attack. These techniques are designed to minimise the risk of detection and prevent the blocking of the entire attack chain.
Its most recent campaign targeted companies in India, Indonesia, South Africa and Russia across industrial, consulting, trade and transportation sectors, where it used phishing emails appearing as official tax audit notifications or to prompt recipients to download an archive purportedly containing a “list of tax violations.” By leveraging the perceived authority and urgency of communications from tax agencies, the threat actor aimed to persuade victims to download the file and trigger the attack chain. Kaspersky’s research recorded more than 1,600 malicious emails between January and February 2026.
Now, recent findings from Kaspersky GReAT showed SilverFox is using fake Claude apps to infiltrate on their target organisations. Claude is an advanced conversational assistant, large language model (LLM), and chatbot developed by Anthropic. It helps users write, code, analyse long documents, and solve complex problems through natural dialogue.
“SilverFox is one of the most active threat groups in the whole APAC region. They get into targets through three simple routes: fake websites, phishing emails, and harmful files spread via social messaging apps. They inject malware used for long-term cyberespionage and sensitive data gathering. Our recent analysis showed they are now distributing fake Claude for Windows, macOS, and Linux, leveraging AI use in companies to crack into their targets’ security defenses,” explains Ye Jin (Seth), lead security researcher at Kaspersky GReAT.
In terms of attack distribution, the APAC region is the hardest hit by SilverFox’s malicious activities, with a volume far exceeding the sum of all other regions. This indicates that current SilverFox threats are mainly concentrated in Asia, particularly in East and Southeast Asia.
“Based on our current threat data, Greater China is SilverFox’s main target with over 90% of all its attacks targeting the region. Mainland China alone makes up 71%. Myanmar, Cambodia and Singapore also see lots of attacks. These are the next hotspots we need to watch,” adds Ye Jin.
When it comes to industry, manufacturing makes up more than one third of all attacks, making it the top target industry for SilverFox. IT and services are closely behind as Kaspersky GReAT researchers see a lot of phishing aimed at tech workers. Healthcare and finance also face big risks from the group known to go after high-value targets.
AI attacks: speed, stealth, and accessibility
Ye Jin also talked about JADEPUFFER, the world's first fully LLM-driven ransomware, which marked a significant turning point in cyber threats. Unlike previous attacks where AI merely augmented human operators, it demonstrated AI acting as both the decision-maker and executor.
As the first agentic ransomware, JADEPUFFER redefined both the speed and sophistication of how cyberattacks happen using AI capabilities. Unlike conventional attacks that still rely on human operators to make decisions or adjust tactics, this attack showed a real-life example of how AI-powered threats can analyse, adapt, and execute attacks in real time.
“In this particular case, disclosed by our Sysdig, the malicious AI agent completed the entire cycle of diagnosing a failed attempt, correcting its approach, and launching a new attack in just 31 seconds, far outpacing the response capabilities of most human defenders. Beyond speed, JADEPUFFER also demonstrates an unprecedented level of autonomy. It shows that AI agents are now capable of making independent decisions throughout the attack process, effectively replicating the reasoning of an experienced human attacker without direct oversight,” he explains.
Aside from speed and autonomy, the rise of agentic AI use in cyberattacks is also writing new rules in terms of stealth and accessibility.
Ye Jin detailed the case of ChatGPhish, an indirect prompt injection technique that transforms trusted AI web-summarization features (like ChatGPT). In these attacks, cybercriminals hide malicious instructions inside webpages and trick users into asking an AI assistant to summarise the content. The AI then unknowingly relays the embedded malicious instructions or links, making it an unintended part of the attack.
Because the malicious content is presented through a trusted AI interface, users are more likely to believe it is safe and click on harmful links or follow dangerous instructions. At the same time, these attacks are difficult for traditional security tools to detect, as they appear to be legitimate interactions between users and AI services rather than conventional cyberattacks.
Malicious AI agents also eliminate the need for technical knowledge to wage a cyberattack. This was proven during the discovery of the AI and cloud-native malware framework VoidLink in January 2026.
Unlike traditional malware that is largely written by human developers, VoidLink was reportedly developed almost entirely with the help of AI, demonstrating how generative AI is transforming the way sophisticated malware can be created and can be democratised.
The need for AI-native defenses
You fight fire with fire. And in this case, Kaspersky expert explains defenders can also utilise AI capabilities to protect enterprise and critical networks against AI-powered cyberattacks.
The four ways companies can counter sophisticated AI-driven threats include:
1. Proactive defense - move beyond passive response and use AI-driven threat hunting to proactively find unknown threats
2. Zero Trust architecture - implement a Zero Trust architecture, verifying every access request strictly to eliminate internal network trust risks
3. Systematic Defense - build a comprehensive defense system covering endpoints, networks, applications, and data.
4. AI vs AI - use large models and dual-use AI technologies to enhance detection and response capabilities, and iterate in real-time with attackers.
“When attackers can leverage AI to automate decision-making and accelerate every stage of an attack, defenders must respond with the same level of intelligence. Cybersecurity solutions enriched with continuously updated threat intelligence are no longer a competitive advantage, but a critical requirement for staying ahead of rapidly evolving threats,” adds Ye Jin.
Tracy