SilverFox Turns AI Trust Into a Cyber Weapon
The rapid adoption of generative AI is creating a new attack surface for enterprises. Security research highlights how SilverFox, an active APT group targeting the Asia-Pacific region, is exploiting interest in AI by distributing fake Claude applications to infiltrate organizations and establish persistent access.
The campaign demonstrates an increasingly effective social-engineering technique: instead of convincing victims to open an obviously suspicious attachment, attackers exploit trust in popular AI brands. Users searching for AI productivity tools can unknowingly download malicious applications, providing attackers with an entry point into corporate environments.
According to the research, more than 90% of observed SilverFox attacks target Greater China, with manufacturing accounting for over one-third of attacks. The group also uses phishing emails, fraudulent websites and malicious files distributed through social-messaging platforms to deploy malware, maintain long-term access and steal sensitive information.
AI Changes the Cyberattack Equation
The larger concern extends beyond SilverFox. AI is helping threat actors accelerate reconnaissance, generate convincing phishing content, develop or modify malware and automate portions of attack workflows. Emerging risks such as indirect prompt injection also demonstrate that AI systems themselves can become new pathways into enterprise applications and data.
This fundamentally changes the economics of cybercrime. Capabilities that previously required specialized expertise can increasingly be assisted by readily available AI tools. At the same time, autonomous AI agents connected to enterprise applications introduce additional risks because compromised or manipulated agents could potentially execute actions at machine speed.
AI Must Fight AI
Traditional security remains essential, but defending AI-era infrastructure requires organizations to move toward AI-native cybersecurity. Kaspersky emphasizes proactive AI-assisted threat hunting, Zero Trust architectures, comprehensive protection, and AI-powered detection and response.
The SilverFox campaign also delivers another important lesson: organizations must protect employees from fake AI applications and shadow AI adoption, not simply secure approved AI platforms. Application control, verified software distribution, endpoint detection, employee awareness and continuous monitoring therefore become critical.
The cybersecurity race is increasingly becoming AI versus AI. As attackers use artificial intelligence to increase speed, scale and sophistication, defenders will need equally intelligent systems capable of identifying abnormal behavior and responding before an automated attack can spread.
The new security principle is clear: Never trust an AI application simply because it carries a trusted AI brand. Verify the application, identity and behavior before granting access.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




