Dangers from SilverFox
Experts from Kaspersky's Global Research and Analysis Group (GReAT) analyzed how SilverFox, one of the strongest APT (intentional cyberattack) groups, takes advantage of the increasingly widespread AI trend in many industries in Asia-Pacific.
SilverFox is known for its method of spreading malware through multiple stages and using separate infrastructure for each stage of the attack, with different addresses and domain names. These techniques help attackers reduce the risk of being detected and avoid the entire attack chain being blocked at the same time.
SilverFox's most recent campaign targets businesses in the fields of industry, consulting, commerce, and transportation in India, Indonesia, South Africa, and Russia. This group uses fraudulent emails forging official tax check notifications or asking recipients to download a compressed file believed to contain a "list of tax violations". Kaspersky's study recorded more than 1,600 malicious emails from January to February 2026.
According to recent findings by security experts, SilverFox is using fake Claude applications to infiltrate the systems of organizations targeted by this group. Claude is an advanced conversation assistant, large-language model (LLM) and chatbot developed by Anthropic. This tool supports users in writing content, programming, long document analysis and solving complex problems through natural conversations.
In terms of the scope of attacks, Asia-Pacific is the area most attacked by SilverFox, with the number of attacks far exceeding the total recorded in all other areas. This shows that SilverFox's operations are currently mainly concentrated in Asia, especially East Asia and Southeast Asia.
Kaspersky security experts also mentioned JADEPUFFER, the world's first ransomware controlled entirely by the Large Language Model (LLM), marking an important turning point for cybersecurity threats. Unlike previous attacks, in which AI mainly played a supporting role for humans, JADEPUFFER shows that AI can both make decisions on its own and directly carry out attacks.
Need to build an AI-integrated defense system right from the foundation
With the motto "using poison to treat poison" in this case, according to Kaspersky experts, the security team can also take advantage of the power of AI to protect business networks and key network systems from AI-based cybersecurity attacks.
Four ways to help businesses cope with sophisticated threats integrated with AI:
- Proactive defense – instead of reacting when an incident occurs. Use AI to proactively scan for threats, thereby detecting unknown threats.
- Zero Trust architecture - deploy Zero Trust architecture, strictly check all access requests to minimize risks arising from defaulting to trusting access inside the internal network.
- Comprehensive defense - building a comprehensive protection system for terminals, networks, applications and data.
- AI versus AI - using large models and AI technology can serve many purposes to improve detection and response capabilities, while continuously adjusting in real time to respond to the attacker's tricks.
