The cyber
threat landscape across APAC remained highly active in the first half of 2026.
Kaspersky detected and blocked 75 million attacks originating from online
resources, including 3.4 million backdoor attacks, 2.4 million password stealer
attacks and 250,000 ransomware incidents. The data comes from Kaspersky
Security Network (KSN), analysed by Kaspersky GReAT.
“While we observed slight declines
in some attack categories during the first half of 2026, this should not be
mistaken for a weakening threat landscape in the region. We are also monitoring
that threat actors are increasingly leveraging AI to automate reconnaissance,
accelerate malware development, and scale attacks, making them faster and more
adaptive,” says Sergey
Lozhkin, Head of APAC and META research units at Kaspersky GReAT.
Globally, APTs
accounted for 24% of high-severity security incidents in 2025, followed by
social engineering (15%) and malware (12%). Kaspersky GReAT monitors more than
900 APT groups worldwide. Five of the 12 most targeted countries globally are
in APAC: China, India, Myanmar, Pakistan and Vietnam.
“APAC as a global leader in digital
transformation and even in AI agent adoption, coupled with its complex
geopolitical environment, makes it a high-value target for threat actors behind
the most advanced persistent threats. The concentration of targeted countries
in the region underscores the strategic value of continuous threat
intelligence, resilient cyber defenses, and stronger regional cooperation,” adds Lozhkin.
Supply chain
attacks are also emerging as a major global concern, with nearly one in three
organisations experiencing a supply chain-related incident over the past year.
Notable incidents involving eScan, Notepad++, Daemon Tools and Axios
demonstrated how attackers can exploit trusted software and open-source
ecosystems to distribute malware and maintain access to victims. The Daemon
Tools campaign alone affected more than 2,000 victims across over 100 countries
and territories.
“We see a rising volume of threats targeting open-source software. In 2025, we detected 19,484 malicious packages, a 37% increase from 14,197 in 2024, while hacktool detections rose 11% year-on-year from 2,966 to 3,302. The findings underscore the growing need for organisations to strengthen software supply chain security as open-source components become increasingly integral to modern applications,” explains Lozhkin.
Kaspersky
recommends organisations strengthen protection through endpoint, EDR and XDR
solutions, managed security services such as MDR and Incident Response, and
comprehensive threat intelligence to identify and respond to evolving cyber
risks.
