Kaspersky reports a surge in cyber threats across Asia-Pacific, highlighting the increasing use of artificial intelligence by attackers and rising supply chain vulnerabilities amid a complex geopolitical and digital landscape.
Kaspersky says cyber threats across the Asia-Pacific region remained intense in the first half of 2026, with its Global Research and Analysis Team blocking 75 million attacks from online resources. The company said the volume included 3.4 million backdoor attempts, 2.4 million password stealer attacks and 250,000 ransomware incidents, underscoring how varied the region’s threat profile has become.
Sergey Lozhkin, who leads Kaspersky GReAT’s APAC and META research units, said modest declines in some categories should not be read as evidence that the danger is easing. He argued that attackers are increasingly using artificial intelligence to speed up reconnaissance and malware creation, a shift that can make campaigns faster to launch and harder to detect. Kaspersky has separately reported rising pressure on industrial systems as well, saying in the first quarter of 2026 that 19.6% of industrial control systems worldwide encountered malicious objects, with Europe and Asia both seeing quarterly increases in attacks on manufacturing.
The company also said APAC remains a key focus for advanced persistent threat groups because of its rapid digital development, growing AI adoption and geopolitical complexity. Kaspersky said five of the 12 most targeted countries globally for APT activity are in the region: China, India, Myanmar, Pakistan and Vietnam. In a separate investigation, Kaspersky’s analysts said they uncovered the TetrisPhantom espionage campaign, which targeted government entities in the region by abusing a secure USB drive to steal sensitive data.
Supply chain attacks featured prominently in Kaspersky’s warning. The company said nearly one in three organisations globally had reported a supply chain-related incident over the past year, with China among the most exposed markets. It cited incidents involving a compromised eScan update server in India, a malicious Notepad++ installer and an active campaign against Daemon Tools that had affected more than 2,000 victims in more than 100 countries. Kaspersky also linked a March 2026 attack on the npm ecosystem involving Axios to techniques previously associated with BlueNoroff, a financially motivated subgroup of Lazarus.
The company said the scale of malicious software discovery remains high. Lozhkin said Kaspersky detected 19,484 malicious open-source packages in 2025, up 37% from 14,197 a year earlier, while detections of hacking tools rose 11% to 3,302. That trend matters because many development teams now depend on open-source software, where one compromised package can ripple through many downstream products. Kaspersky said it is expanding its open-source threat feed to help organisations spot vulnerabilities, malicious packages and hacking tools earlier in the development process.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





