Warning of malware from fake Claude AI application

NGUYỄN ĐĂNG |

Security experts have analyzed that the SilverFox hacker group is using fake Claude malware to infiltrate organizations in Asia - Pacific.

Dangers from SilverFox

Experts from Kaspersky's Global Research and Analysis Group (GReAT) analyzed how SilverFox, one of the strongest APT (intentional cyberattack) groups, takes advantage of the increasingly widespread AI trend in many industries in Asia-Pacific.

SilverFox is known for its method of spreading malware through multiple stages and using separate infrastructure for each stage of the attack, with different addresses and domain names. These techniques help attackers reduce the risk of being detected and avoid the entire attack chain being blocked at the same time.

SilverFox's most recent campaign targets businesses in the fields of industry, consulting, commerce, and transportation in India, Indonesia, South Africa, and Russia. This group uses fraudulent emails forging official tax check notifications or asking recipients to download a compressed file believed to contain a "list of tax violations". Kaspersky's study recorded more than 1,600 malicious emails from January to February 2026.

According to recent findings by security experts, SilverFox is using fake Claude applications to infiltrate the systems of organizations targeted by this group. Claude is an advanced conversation assistant, large-language model (LLM) and chatbot developed by Anthropic. This tool supports users in writing content, programming, long document analysis and solving complex problems through natural conversations.

In terms of the scope of attacks, Asia-Pacific is the area most attacked by SilverFox, with the number of attacks far exceeding the total recorded in all other areas. This shows that SilverFox's operations are currently mainly concentrated in Asia, especially East Asia and Southeast Asia.

Kaspersky security experts also mentioned JADEPUFFER, the world's first ransomware controlled entirely by the Large Language Model (LLM), marking an important turning point for cybersecurity threats. Unlike previous attacks, in which AI mainly played a supporting role for humans, JADEPUFFER shows that AI can both make decisions on its own and directly carry out attacks.

Need to build an AI-integrated defense system right from the foundation

With the motto "using poison to treat poison" in this case, according to Kaspersky experts, the security team can also take advantage of the power of AI to protect business networks and key network systems from AI-based cybersecurity attacks.

Four ways to help businesses cope with sophisticated threats integrated with AI:

- Proactive defense – instead of reacting when an incident occurs. Use AI to proactively scan for threats, thereby detecting unknown threats.

- Zero Trust architecture - deploy Zero Trust architecture, strictly check all access requests to minimize risks arising from defaulting to trusting access inside the internal network.

- Comprehensive defense - building a comprehensive protection system for terminals, networks, applications and data.

- AI versus AI - using large models and AI technology can serve many purposes to improve detection and response capabilities, while continuously adjusting in real time to respond to the attacker's tricks.

NGUYỄN ĐĂNG
RELATED NEWS

15,000 reader codes in the form of AI Agent software detected: Network security alarm

|

According to Kaspersky experts, AI has become a core part of cybersecurity threats, while contributing to shaping the future of cybersecurity.

Extortion malware threatens Southeast Asian businesses

|

The latest data from Kaspersky shows that ransomware is the leading threat to small and medium-sized enterprises (SMB) in Southeast Asia.

Detecting a large-scale malware distribution campaign through WhatsApp

|

Security company Kaspersky has just discovered a malware distribution campaign targeting WhatsApp Desktop and WhatsApp Web users.

Hue University reviews the use of foreign language certificates for admission 2026

|

Hue - Hue University is reviewing cases of using foreign language certificates in official university admissions in 2026.

97 years of Lao Dong Newspaper's historical journey

|

97 years ago, on August 14, 1929, in a small house in Thong Phong alley, near Ho Giam Lake (Hanoi), the first issue of Lao Dong Newspaper was born under the direction of comrade Nguyen Duc Canh. From that moment, a historical journey began. The journey of the revolutionary newspaper always accompanied the working class and working people, in every stage of the country's development.

Unexpected reaction of violators when reviewing errors at cold fine handling points

|

Hanoi - Seeing firsthand the images of violations recorded by cameras at the cold fine handling location, many people were surprised because they did not expect to make that mistake.

Central defender Que Ngoc Hai believes Dinh Bac will become an excellent player of Vietnam

|

Central defender Que Ngoc Hai encourages the Vietnamese team before the ASEAN Cup 2026 semi-final, believing Dinh Bac will become an excellent player of the national team.

15,000 reader codes in the form of AI Agent software detected: Network security alarm

NGUYỄN ĐĂNG |

According to Kaspersky experts, AI has become a core part of cybersecurity threats, while contributing to shaping the future of cybersecurity.

Extortion malware threatens Southeast Asian businesses

NGUYỄN ĐĂNG |

The latest data from Kaspersky shows that ransomware is the leading threat to small and medium-sized enterprises (SMB) in Southeast Asia.

Detecting a large-scale malware distribution campaign through WhatsApp

NGUYỄN ĐĂNG |

Security company Kaspersky has just discovered a malware distribution campaign targeting WhatsApp Desktop and WhatsApp Web users.