Kaspersky has recorded a 111 per cent surge in spyware attacks targeting organisations in Singapore in 2025, the highest year-on-year increase across Southeast Asia, as cybercriminals increasingly shift focus from business disruption to intelligence gathering.
Kaspersky business solutions blocked a total of 30,691 spyware attack attempts against Singapore-based organisations last year. Across the broader Southeast Asia region, the firm detected more than 818,000 attacks in 2025 — an 18 per cent increase from 2024.
Southeast Asia Under Growing Spyware Threat
The regional picture is uneven. Malaysia saw spyware attacks rise 75 per cent year-on-year, the Philippines 85 per cent, and Indonesia 35 per cent. Vietnam recorded a more modest 8 per cent increase. Thailand was the only country to see a decline, with attacks falling 53 per cent. Singapore’s 111 per cent spike was the sharpest in the region.
Kaspersky experts attribute the trend to a strategic shift among threat actors, who are increasingly exploiting corporate networks for sensitive data and intelligence rather than causing operational disruption.
We are entering an era of threat actors looking beyond business disruption. We are seeing a rise in targeted intelligence gathering in SEA, turning corporate networks into rich hunting grounds for sensitive information.
— Simon Tung, General Manager for ASEAN and Asia Emerging Countries, Kaspersky
Operation ForumTroll: A Case Study in Cyberespionage
In March 2025, Kaspersky uncovered Operation ForumTroll, a targeted cyberespionage campaign that exploited a Chrome zero-day vulnerability to infiltrate organisations across media, government, education, and finance. Attackers used personalised phishing emails disguised as invitations to the Primakov Readings forum, deploying spyware tools including LeetAgent and a more advanced variant known as Dante — both linked through shared infrastructure, pointing to a coordinated, well-resourced operation.
The campaign illustrates how advanced spyware enables attackers to monitor systems quietly, capture sensitive data, and track internal communications over extended periods — turning a single infection into a sustained breach of operational security.
Recommendations for Organisations
- Keep all software updated across devices to prevent exploitation of known vulnerabilities
- Avoid exposing remote desktop services to public networks; enforce strong passwords where RDP is necessary
- Deploy advanced endpoint security with cross-infrastructure visibility to detect and neutralise complex threats
- Use current threat intelligence to stay aware of adversary tactics, techniques, and procedures
- Back up corporate data regularly, keeping backups isolated from the network

