< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 5 sources · 22 days · First seen · Last updated

SilverFox cyber-espionage group activity

Overview

The SilverFox cyber-espionage group has expanded its operational capabilities and geographic reach across the Asia-Pacific region. Initially, the group targeted Japanese industrial manufacturers using the ValleyRAT remote-access trojan. This campaign utilized phishing emails and a sophisticated “bring-your-own-vulnerable-driver” (BYOVD) chain to achieve kernel-level execution and maintain persistence by bypassing security tools.

More recent activity indicates a shift toward integrating artificial intelligence to accelerate attacks. The group has been observed distributing fraudulent AI applications, such as fake versions of the Claude assistant, to infiltrate corporate networks. New AI-powered tools have been identified, including the JADEPUFFER ransomware agent, the prompt-injection tool ChatGPhish, and the cloud-based malware framework VoidLink.

While the group previously targeted Japanese industry, recent data shows China as the primary target, accounting for 90% of attacks, alongside significant activity in Myanmar, Cambodia, and Singapore. The manufacturing sector remains a frequent target, alongside IT, healthcare, and finance.

Entities

Cato Networks · Kaspersky · Japanese industrial manufacturer · China · SilverFox

Timeline

  1. 19 days ago

    [TECHNOLOGY] 5 sources
    SilverFox group uses AI to accelerate cyberattacks in Asia-Pacific

    Kaspersky reports a rise in AI-powered cyberattacks in Asia-Pacific, led by the SilverFox group using fake AI apps and autonomous ransomware to target manufacturing and IT sectors, primarily in China.

  2. about 1 month ago

    [TECHNOLOGY] 2 sources
    Silver Fox targets Japanese industrial maker with ValleyRAT malware

    Chinese APT Silver Fox used a novel BYOVD chain with three kernel drivers to deliver ValleyRAT to a Japanese industrial manufacturer, starting with a phishing invoice and DLL sideloading via Zeon‑signed tools.

Sources

cnbcindonesia.com · medcom.id · mediaindonesia.com · technologue.id · viva.co.id