August 7, 2026 | 07:00 am

TEMPO.CO, Jakarta - The Asia-Pacific (APAC) region has become a major hub of activity for SilverFox, a China-linked advanced persistent threat (APT) group known for developing and modifying its own malware to evade conventional security detection.
Cybersecurity firm Kaspersky said attacks by SilverFox have become increasingly concentrated in Greater China and Southeast Asia. The group, which operates at a sophisticated level beyond typical cybercriminal activity, has been known to customize malware such as ValleyRAT and Winos to bypass standard antivirus systems.
Kaspersky GReAT Lead Security Researcher Jin Ye said SilverFox has primarily targeted the manufacturing sector, with attacks commonly carried out through phishing campaigns, compromised websites, and malicious IP addresses.
"The attacks we hear about almost every day involve three simple methods: regular phishing, phishing through major websites, and attacks through IP addresses," Jin said during a session at Kaspersky's Cyber Security Weekend APAC 2026 in Guangzhou, China, on Monday, Aug. 3, 2026.
According to Jin, about 60.4 percent of SilverFox's global attack activity occurred in the Asia-Pacific region, particularly East and South Asia. The figure was significantly higher than North America's 18.8 percent share and Europe's 16.3 percent.
China and Southeast Asia Emerge as Key Targets
Within the Asia-Pacific region, 91.2 percent of SilverFox attacks were detected in mainland China, Hong Kong, Taiwan, and Macao.
Jin also highlighted emerging cyber threat hotspots in Southeast Asia, with Singapore, Myanmar, and Cambodia becoming new areas of concern for SilverFox-related activity.
Kaspersky data showed that the group does not target all industries equally. Manufacturing accounted for 36.6 percent of recorded attacks, followed by IT services at 14.5 percent and general business sectors at 13.8 percent.
"The healthcare and financial sectors, which hold high-value data, also have the potential to become targets for attackers," Jin said.
SilverFox has also been linked to the distribution of fake Claude applications for Windows, macOS, and Linux. The applications, designed to imitate Anthropic's AI chatbot, were used as tools for broader cyberattacks and sensitive data collection.
AI-Powered Cyber Threats Raise Security Concerns
Kaspersky APAC Managing Director Adrian Hia said hackers using artificial intelligence technology are now moving faster than many corporate security teams can detect and respond to threats.
"Cybersecurity is no longer just a race against time, but also a race against invisibility," Adrian said during the same event.
He said Kaspersky detected and blocked an average of 500,000 unique malicious files every day throughout 2025, representing a 7 percent increase from 2024.
Adrian cited AI-driven cyberattacks that disrupted the logistics chain of Japan's frozen food company Nichirei Corp. Similar large-scale ransomware threats have also affected manufacturing operations and IT systems in India.
In 2026, Kaspersky identified more than 15,000 malware samples disguised as AI agent software. Adrian warned that the growing reliance of AI agents on application programming interfaces (APIs) and third-party plugins could create new vulnerabilities.
"When one upstream component is compromised, the impact can trigger a domino effect that damages multiple downstream systems," he said.
As AI adoption accelerates, cybersecurity experts warn that companies will need stronger defenses to address increasingly sophisticated attacks that combine automation, malware, and social engineering techniques.
Montenegro Arrests Iran-Linked Hacker Wanted by US
41 hari lalu

The FBI helped Montenegro detain an Iranian-Turkish national accused of cyberattacks on US infrastructure causing billions in damages.
ICSF Uncovers Rampant Hacker-for-Hire Trade in Indonesia
50 hari lalu

The Indonesia Cyber Security Forum (ICSF) noted that numerous "hacker-for-hire" groups are operating like digital mercenaries.
Pornhub Premium Users Face Data Risk After Third-Party Cyber Breach
23 Desember 2025

The hacker group Shiny Hunters has breached the third-party analytics vendor Mixpanel affiliated with Pornhub.
How Hackers Breach Accounts in Six Banks
29 November 2025

A hacker syndicate robbed Rp800 billion from eight banks. Authorities suspect they exploited flaws in the BI-Fast system.
Indonesia's Purbaya Will Ask Ministries to Hire Hackers to Boost Cybersecurity
24 Oktober 2025

Purbaya revealed that the Ministry of Finance has involved several Indonesian hackers to help improve the system's cybersecurity.
Finance Minister Hires Ethical Hackers to Strengthen Indonesia's Coretax System
24 Oktober 2025

According to Minister Purbaya, this step is taken to detect and fix various weaknesses in the Coretax program and application code.
Safenet: Bjorka's Claims Reveal Weaknesses in Indonesian National Police's Digital Security System
8 Oktober 2025

A person claiming to be the notorious hacker Bjorka has claimed to have released the data of 341,000 Indonesian Police personnel.
Jakarta Police to Probe Alleged 341,000 Personnel Data Leak by Hacker Bjorka
6 Oktober 2025

Police are investigating the hacking and dissemination of the personal data of 341,000 Indonesian police personnel by the hacker Bjorka, after the Jakarta Metro Police Department arrested a man who claimed to be the owner of the account X Bjorka.
Police Cannot Yet Confirm True Identity of Hacker Bjorka
5 Oktober 2025

The Jakarta Metropolitan Police arrested a man with the initials WFT on suspicion of being the hacker known as Bjorka.
Hacker Bjorka Breaches Personal Data of 341,000 Indonesian National Police Personnel
5 Oktober 2025

Based on Tempo's investigation, Bjorka released the data of hundreds of thousands of Indonesian National Police personnel for free on Saturday, October 4th, 2025.


















































