Kaspersky Blocked 250,000 Ransomware Hits in APAC

Kaspersky detected and blocked 75 million attacks originating from online resources across Asia Pacific in the first half of 2026, including 250,000 ransomware incidents, 3.4 million backdoor attacks and 2.4 million password stealer attacks, according to new data from the company’s Global Research and Analysis Team (GReAT).

The figures, drawn from the Kaspersky Security Network and analysed between January and June, point to a threat landscape that remains highly active across the region even as some individual attack categories saw slight declines during the period.

AI-accelerated attacks and a region under strategic pressure

Sergey Lozhkin, Head of APAC and META research units at Kaspersky GReAT, said the slight dip in some categories should not be read as a cooling threat environment.

“We are also monitoring that threat actors are increasingly leveraging AI to automate reconnaissance, accelerate malware development, and scale attacks, making them faster and more adaptive,” said Sergey Lozhkin, Head of APAC and META research units, Kaspersky GReAT.

Kaspersky’s GReAT team monitors more than 900 advanced persistent threat (APT) groups worldwide, and said five of the 12 most targeted countries globally for APT activity are in APAC: China, India, Myanmar, Pakistan and Vietnam. Globally in 2025, the top three categories of high-severity security incidents were APT activity (24 per cent), social engineering (15 per cent) and malware (12 per cent).

“APAC as a global leader in digital transformation and even in AI agent adoption, coupled with its complex geopolitical environment, makes it a high-value target for threat actors behind the most advanced persistent threats,” Lozhkin added.

Supply chain attacks emerge as a leading global threat

Kaspersky also flagged supply chain attacks as one of the most common cyber threats facing businesses worldwide, with nearly one in three organisations reporting a related incident over the past year. Recent cases highlighted by GReAT include:

  • A compromise of eScan’s antivirus update infrastructure used to distribute malware to customers
  • A malicious Notepad++ installer delivering a Trojan backdoor that persisted on affected systems for months
  • An ongoing attack on the official Daemon Tools website, active since April 2026, affecting more than 2,000 victims across over 100 countries
  • A compromise of a lead maintainer’s npm account for Axios, a JavaScript library with over 100 million weekly downloads, used to publish malicious package versions

Kaspersky said it detected 19,484 malicious open-source packages in 2025, a 37 per cent increase from 14,197 in 2024, alongside an 11 per cent year-on-year rise in hacktool detections. The company recommended organisations in the region adopt layered detection and response tools, managed security services, and threat intelligence feeds to strengthen visibility against increasingly AI-assisted and supply chain-driven attacks.

Author


Discover more from techcoffeehouse.com

Subscribe to get the latest posts sent to your email.

Use promo code “TCH15” to get 15% off on checkout.

Share your thoughts

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading