Where Is SilverFox Attacking? Mapping the Hacker Group's APAC Targets
Summarized and contextualized by DistantNews.
At a glance
- The Asia-Pacific (APAC) region, particularly Greater China and Southeast Asia, is experiencing a surge in cyberattacks from SilverFox, a China-linked advanced persistent threat (APT) group.
- SilverFox specializes in customizing malware like ValleyRAT and Winos to evade detection and primarily targets the manufacturing sector through phishing, compromised websites, and malicious IP addresses.
- The group is also leveraging AI-powered tools and fake applications, raising concerns about the increasing speed and sophistication of cyber threats outpacing corporate defenses.
The Asia-Pacific region has become a focal point for SilverFox, a sophisticated cyber threat group with ties to China, according to cybersecurity firm Kaspersky. The group is noted for its ability to develop and modify its own malware, including tools like ValleyRAT and Winos, specifically to bypass standard security measures. This advanced capability allows SilverFox to operate beyond the scope of typical cybercriminal activities.
Kaspersky researchers observed that SilverFox's attacks are increasingly concentrated in Greater China and Southeast Asia. Jin Ye, Lead Security Researcher at Kaspersky GReAT, stated that the group primarily targets the manufacturing sector. Attacks are commonly executed through phishing campaigns, exploiting compromised websites, and utilizing malicious IP addresses. "The attacks we hear about almost every day involve three simple methods: regular phishing, phishing through major websites, and attacks through IP addresses," Jin explained during a session at Kaspersky's Cyber Security Weekend APAC 2026.
Globally, the Asia-Pacific region accounted for a significant 60.4 percent of SilverFox's attack activity, far exceeding North America's 18.8 percent and Europe's 16.3 percent. Within APAC, mainland China, Hong Kong, Taiwan, and Macao saw 91.2 percent of these attacks. Emerging hotspots in Southeast Asia include Singapore, Myanmar, and Cambodia. While manufacturing is the most targeted industry at 36.6 percent, IT services and general business sectors are also affected. Jin noted that high-value data sectors like healthcare and finance also hold potential as future targets.
The attacks we hear about almost every day involve three simple methods: regular phishing, phishing through major websites, and attacks through IP addresses.
SilverFox is also implicated in distributing fake Claude applications for various operating systems, mimicking Anthropic's AI chatbot to collect sensitive data and facilitate broader cyberattacks. This trend highlights the growing use of AI in cyber threats. Adrian Hia, Kaspersky APAC Managing Director, warned that AI-powered attacks are evolving faster than many corporate security teams can respond. "Cybersecurity is no longer just a race against time, but also a race against invisibility," Adrian remarked.
Kaspersky blocked an average of 500,000 unique malicious files daily in 2025, a 7 percent increase from the previous year. The firm identified over 15,000 malware samples disguised as AI agent software in 2026. Adrian cautioned that the reliance of AI agents on APIs and third-party plugins creates new vulnerabilities, potentially leading to domino effects when upstream components are compromised. As AI adoption accelerates, experts stress the need for stronger defenses combining automation, malware, and social engineering.
Cybersecurity is no longer just a race against time, but also a race against invisibility.
Originally published by Tempo. Summarized and contextualized by our editorial team with added local perspective. Read our editorial standards.