Kaspersky’s latest threat intelligence report highlights millions of backdoor, password-stealing and ransomware attacks across the region, while AI-driven threats and software supply chain compromises add to the growing cybersecurity risks.
Kaspersky blocked 75 million cyberattacks originating from online resources across Asia Pacific during the first six months of 2026, highlighting the region’s continued exposure to sophisticated and large-scale cyber threats.
According to data from the Kaspersky Security Network analysed by the company’s Global Research and Analysis Team (GReAT), the security firm detected and stopped 3.4 million backdoor attacks, 2.4 million password-stealing attacks and around 250,000 ransomware incidents between January and June.
While some categories recorded fluctuations during the period, Kaspersky warned that the overall threat environment remains active. Sergey Lozhkin, Head of APAC and META research units at Kaspersky GReAT, said attackers are increasingly using artificial intelligence to automate reconnaissance, speed up malware development and scale attacks.
APAC remains a key target
The region’s rapid digital transformation and growing adoption of AI are making it an attractive target for advanced threat groups. Kaspersky noted that advanced persistent threats (APTs) accounted for 24% of high-severity security incidents globally in 2025, followed by social engineering at 15% and malware at 12%.
Five of the 12 countries most targeted by APT activity are located in APAC — China, India, Myanmar, Pakistan and Vietnam. Kaspersky said the region’s digital growth, AI adoption and geopolitical complexity are contributing to its strategic importance for sophisticated attackers.
APT campaigns typically involve gaining unauthorised access to networks and maintaining a hidden presence over an extended period. They can be used for cyber espionage, sensitive data theft and other long-term objectives. Kaspersky’s GReAT currently monitors more than 900 APT groups worldwide.
The company is also tracking growing risks linked to software supply chains. Its research found that nearly one in three organisations globally experienced a supply chain-related incident during the past year. China was among the countries reporting high exposure, with 40% of businesses identifying supply chain risks.
Several recent incidents demonstrate the scale of the problem. Attackers compromised eScan’s antivirus update infrastructure to distribute malware, while a malicious installer associated with Notepad++ was used to deploy a backdoor. Kaspersky also identified an ongoing campaign involving the Daemon Tools website that reportedly affected more than 2,000 victims across more than 100 countries and territories.
Open-source software faces growing threats
Open-source software is another area attracting increasing attention from cybercriminals. Kaspersky detected 19,484 malicious packages in 2025, up 37% from 14,197 in 2024. Hacktool detections also increased 11% to 3,302.
The Axios supply chain compromise was among the notable incidents. Attackers gained access to the npm account of a lead maintainer and used it to publish malicious versions of the widely used JavaScript library. Kaspersky researchers identified technical similarities between the incident and previously documented BlueNoroff campaigns.
Kaspersky said organisations should strengthen software supply chain security alongside conventional cybersecurity measures. It recommends continuous threat intelligence, stronger endpoint protection, managed detection and response services, and incident-response capabilities.
With cybercriminals increasingly combining AI with established attack methods, the latest figures underline the need for organisations across APAC to improve their ability to detect, investigate and respond to threats before they cause wider damage.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




