Cybercriminal group SilverFox is using fake Claude AI applications to break into businesses across Asia-Pacific (APAC), as attackers increasingly exploit the growing use of artificial intelligence (AI) in the workplace, according to cybersecurity company Kaspersky.

Researchers from Kaspersky’s Global Research and Analysis Team (GReAT) said the group is distributing fake Claude applications for Windows, macOS, and Linux through fake websites, phishing emails, and malicious files shared on messaging platforms.

“SilverFox is one of the most active threat groups in the whole APAC region. They get into targets through three simple routes: fake websites, phishing emails, and harmful files spread via social messaging apps,” said Ye Jin (Seth), lead security researcher at Kaspersky GReAT. 

Ye Jin also noted that SilverFox injects malware used for long-term cyberespionage and sensitive data gathering. 

“Our recent analysis showed they are now distributing fake Claude for Windows, macOS, and Linux, leveraging AI use in companies to crack into their targets’ security defenses,” Ye Jin said.

APAC is the group’s main target. More than 90% of its attacks are aimed at Greater China, while Myanmar, Cambodia, and Singapore are also among the affected markets. Manufacturing is the most targeted industry, followed by IT services, healthcare, and finance.

Kaspersky also warned that AI is making cyberattacks faster and easier to launch. Ye Jin specifically mentioned JADEPUFFER, described as the world’s first fully LLM-driven ransomware, which was able to analyze a failed attack, adjust its tactics, and launch another attack in just 31 seconds.

Kaspersky also highlighted ChatGPhish, a technique that hides malicious instructions inside web pages. When users ask an AI assistant to summarize the page, the AI may unknowingly pass along harmful links or instructions, making the attack appear legitimate.

To reduce the risk, Kaspersky recommends AI-driven threat hunting, Zero Trust security, protection across endpoints, networks, applications, and data, and using AI to improve threat detection and response.

“When attackers can leverage AI to automate decision-making and accelerate every stage of an attack, defenders must respond with the same level of intelligence. Cybersecurity solutions enriched with continuously updated threat intelligence are no longer a competitive advantage, but a critical requirement for staying ahead of rapidly evolving threats,” Ye Jin said.

Discover more from Back End News

Subscribe now to keep reading and get access to the full archive.

Continue reading