Fake Claude apps are being distributed by the SilverFox threat group as part of a campaign targeting organizations across Asia Pacific, according to researchers from Kaspersky’s Global Research and Analysis Team. The malicious applications imitate Claude, the generative artificial intelligence assistant developed by Anthropic.
SilverFox reportedly offers fraudulent versions for Windows, macOS and Linux, allowing the group to exploit growing business interest in workplace AI tools.
Kaspersky researchers warn that employees looking for AI software could unknowingly download these fake Claude apps from fraudulent websites, phishing messages or links shared through social messaging services. Once installed, the malicious software can give attackers a route into company systems for cyberespionage and sensitive data collection.
What are Fake Claude Apps?
Fake Claude apps are malicious programs designed to resemble legitimate applications associated with Anthropic’s Claude AI assistant. Claude is a large language model that helps users write, generate code, analyze lengthy documents, and solve problems through natural-language conversations. Its growing use within businesses makes it an attractive name for cybercriminals to imitate.
A fake app may copy Claude’s branding, interface or installation process. However, the downloaded file can contain malware designed to steal information, establish remote access or create a persistent presence on the victim’s device.
The danger is not limited to employees deliberately installing unauthorized software. Attackers may promote fake Claude apps through search results, convincing download pages, phishing emails and messages that appear to come from colleagues or trusted contacts.
Users should obtain Claude software only through Anthropic’s verified website or an application source approved by their employer.
SilverFox Exploits Growing Demand for AI Tools
Kaspersky describes SilverFox as one of the most active advanced persistent threat groups operating in Asia Pacific.
“SilverFox is one of the most active threat groups in the whole APAC region,” said Jin Ye, also known as Seth, lead security researcher at Kaspersky GReAT.
“They get into targets through three simple routes: fake websites, phishing emails and harmful files spread via social messaging apps. They inject malware used for long-term cyberespionage and sensitive data gathering.”
According to Jin Ye, SilverFox is now distributing fake Claude apps for Windows, macOS and Linux. The tactic takes advantage of the rapid adoption of generative AI across companies and industries.
Employees may be particularly vulnerable when an organization has not established clear rules governing AI use. If workers are unsure which tools are approved or where they should download them, a convincing fake application can appear legitimate.
The presence of versions for multiple operating systems also widens the potential target pool. SilverFox is not limiting its campaign to conventional Windows-based corporate environments but is also attempting to reach Mac and Linux users.
How Fake Claude Apps Compromise Businesses
An attack involving fake Claude apps typically begins before the malicious program reaches a company device. SilverFox may direct potential victims to a fraudulent website that resembles a legitimate AI download page. The group can also deliver links through phishing emails or social messaging platforms, where recipients may be less cautious than they are with corporate email.
The victim is then encouraged to download and install what appears to be a useful AI application. Because legitimate AI tools often need internet access and permission to process files, some suspicious behavior may not immediately attract attention. Once the malicious file runs, it can trigger a multi-stage attack.
Rather than delivering every malicious component simultaneously, the initial program may connect to separate domains or servers to retrieve additional payloads. This segmented method can make the attack harder to detect and disrupt. Blocking one address may stop only a single stage, leaving other parts of the supporting infrastructure intact.
SilverFox reportedly uses its malware to maintain long-term access, conduct cyberespionage and gather sensitive information. Depending on the victim’s role and access privileges, the exposed data could include internal documents, credentials, communications or commercially valuable information.
SilverFox Previously Impersonated Tax Authorities
The use of fake Claude apps follows earlier SilverFox campaigns that relied on official-looking tax notices. Kaspersky detected the threat actor in December 2025 and subsequently examined a campaign targeting organizations in India, Indonesia, South Africa and Russia. The affected companies operated across industrial, consulting, trade and transportation sectors.
Some phishing emails were designed to look like official tax audit notifications. Others encouraged recipients to download an archive supposedly containing a list of tax violations. These messages combined authority with urgency. Employees who believed their organization was facing an audit, investigation, or penalty might have opened the files before checking whether the sender was genuine.
Kaspersky recorded more than 1,600 malicious emails associated with this activity between January and February 2026.
SilverFox’s move from tax-themed phishing to fake Claude apps shows that its social-engineering methods can change according to current business interests. The underlying objective remains similar: convince the victim to run a malicious file voluntarily.
Asia Pacific is The Main Target
Asia Pacific accounts for most of the malicious activity attributed to SilverFox, according to Kaspersky’s threat data. The recorded attack volume in the region reportedly exceeds the combined figure for every other region. Greater China is a major focus, representing more than 90% of observed attacks. Mainland China alone accounts for 71%.
Myanmar, Cambodia and Singapore are also among the locations seeing notable SilverFox activity. These figures indicate that the group is concentrating heavily on East and Southeast Asia.
Malaysia was not identified as a principal hotspot in the information released by Kaspersky. Nevertheless, Malaysian organizations face related risks because they operate within an interconnected regional economy.
A company does not need to be directly targeted to suffer the effects of a breach. Compromised suppliers, technology providers, logistics businesses and professional services firms can expose their customers and commercial partners to additional attacks.
Fake Claude apps may also circulate across borders through search engines, shared messaging groups and software download websites. Organizations throughout the region should therefore treat the campaign as relevant even when local attack numbers appear comparatively low.
Manufacturing Faces The Brunt of SilverFox Attacks
Manufacturing accounts for more than one-third of observed SilverFox attacks, making it the threat group’s largest industry target. Manufacturers can hold valuable intellectual property, production data, and information about suppliers or customers. Their operational dependence on connected technology can also make prolonged disruption particularly costly.
Information technology and service companies follow closely. Kaspersky researchers have observed extensive phishing activity aimed at technology workers, who may have privileged access to systems or greater freedom to install development and productivity tools.
Software developers and IT professionals may also be more interested in downloading an AI assistant. Claude can be used for coding, troubleshooting and document analysis, making fake Claude apps potentially convincing within technical teams.
Healthcare and financial organizations are also exposed. Both sectors hold high-value information, including personal records, payment data and confidential business material.
Warning Signs of a Fake Claude Download
A webpage offering Claude software should not be trusted simply because it uses professional graphics or familiar branding. Modern phishing websites can reproduce the appearance of legitimate services with considerable accuracy.
An unexpected domain name is one of the clearest warning signs. Attackers frequently register addresses that contain misspellings, extra words or unusual domain extensions intended to resemble a vendor’s official website.
Employees should also be suspicious of Claude installers delivered as compressed archives through email or messaging apps. Legitimate business software should be obtained through a verified vendor channel or the organization’s managed software catalog.
Requests to disable antivirus software, bypass an operating system warning or grant unnecessary administrative privileges are further indicators of risk. Pressure to install an application immediately should also prompt additional verification.
A file can still be dangerous even when it displays a familiar icon or appears to run a working interface. Cybercriminals may package malicious components with software that looks functional to avoid raising suspicion.
AI Brands are Becoming Valuable Phishing Bait
Fake Claude apps are part of a wider trend in which cybercriminals exploit demand for popular AI products. Businesses are rapidly adopting AI for writing, programming, research, customer support and data analysis. Employees may try new services before their employers have completed a formal security assessment.
This gap creates an opportunity for attackers. A fraudulent AI tool can appear timely, useful, and credible, particularly when it imitates a recognized product.
The strategy does not require attackers to breach Anthropic or compromise the legitimate Claude platform. They only need to persuade potential victims that an unofficial website or installer is connected to the real service.
Organizations should therefore apply the same software controls to AI tools that they use for other business applications. AI adoption should not take place through informal downloads, or links passed between employees.
AI is Also Accelerating Cyberattacks
SilverFox is exploiting AI as a theme, but researchers have found other attacks in which AI plays a more operational role. JADEPUFFER, documented by Sysdig researchers, has been described as the first observed agentic ransomware operation driven from beginning to end by a large language model.
Traditional cyberattacks commonly depend on human operators to interpret results and adjust tactics. JADEPUFFER showed how an AI agent could analyze an unsuccessful action, identify the problem and execute a revised approach.
During one sequence, the malicious agent reportedly moved from a failed login to a working correction in 31 seconds. The operation also conducted reconnaissance, searched for credentials, moved between systems and carried out a destructive database-extortion attack.
Such automation could allow criminals to run more operations while responding to technical obstacles much faster. It may also reduce the cost of carrying out attacks that previously required several experienced specialists.
Trusted AI Responses Can Be Dangerous
Indirect prompt injection presents another emerging threat.
In this type of attack, a criminal places hidden instructions within a webpage or document. A user then asks an AI assistant to analyze or summarise the affected content.
If the AI follows the concealed prompt, it may reproduce a malicious link or tell the user to perform a dangerous action. The user could be more inclined to trust the instruction because it appears inside a recognized AI interface.
Jin Ye cited ChatGPhish as an example of how trusted AI summarisation features could be manipulated in phishing attacks.
These interactions may also be difficult for conventional security systems to identify. The visible activity can resemble a legitimate exchange between a user and an approved AI service rather than a conventional malicious email.
Users should not assume that an AI-generated answer has verified every link or instruction it contains. Any request involving software installation, credentials, payments, or sensitive files should be checked against an independent source.
How to Defend Against Fake Claude Apps
Businesses can reduce their exposure by establishing a clear list of approved AI products and giving employees direct access to verified installation channels.
Application controls can prevent unauthorized executables from running, while restricted administrative privileges can limit the damage caused by a malicious installer. Email, web and endpoint security systems should also be configured to inspect compressed archives and recently downloaded applications.
Security teams should monitor for newly registered domains that imitate Claude, Anthropic and other widely used AI brands. Blocking known malicious domains alone may be insufficient because groups such as SilverFox use segmented infrastructure and can replace individual addresses.
A Zero Trust approach provides another layer of protection. Every user, device, and application should be verified before accessing sensitive resources, even when the request originates from within the company network.
Organizations should also monitor unusual outbound connections and unexpected activity from AI-related applications. A supposedly legitimate assistant communicating with unknown servers or accessing unrelated files should trigger an investigation.
Regular employee training remains essential. Staff should know where to obtain approved AI applications, how to recognize fraudulent download pages, and whom to contact when they encounter unfamiliar software.
Fake Claude Apps Show AI Adoption Needs Governance
The SilverFox campaign demonstrates that AI adoption is now closely connected to cybersecurity. Businesses want employees to benefit from tools such as Claude, but unclear policies can encourage workers to find and install applications independently. Attackers can then exploit the confusion with convincing fake Claude apps.
A company’s response should not be to prohibit every AI tool without considering how employees work. Excessively restrictive policies may push AI use into unmonitored channels. A safer approach is to provide approved services, verified downloads and practical guidance.
As AI assistants become more familiar, their names and interfaces will carry greater trust. Cybercriminals will continue trying to borrow that trust to distribute malware.
Organizations across Asia Pacific should consequently treat every unofficial AI download as a potential security risk. When a fake Claude app can provide an entry point for espionage and data theft, verifying the software source must become a routine part of using AI at work.





