Threat actors have been busy during the first half of 2026, waging various attacks against companies and individuals in Asia Pacific (APAC). Recent data from Kaspersky showed a slight increase in backdoors, more than 2 million password stealers, and a quarter of a million ransomware attacks foiled in the region from January to June. Kaspersky’s Global Research and Analysis Team (GReAT) also warns against the rising attacks on supply chains, globally.
The cyber threat landscape across APAC remained highly active in the first half of 2026, with Kaspersky detecting and blocking 75 million attacks originating from online resources. The findings also revealed that 3.4 million backdoor attacks, 2.4 million password stealer attacks, and 250,000 ransomware incidents were prevented during the six-month period.
The data are from Kaspersky Security Network (KSN) analysed by Kaspersky GReAT.
“While we observed slight declines in some attack categories during the first half of 2026, this should not be mistaken for a weakening threat landscape in the region. We are also monitoring that threat actors are increasingly leveraging AI to automate reconnaissance, accelerate malware development, and scale attacks, making them faster and more adaptive,” says Sergey Lozhkin, Head of APAC and META research units at Kaspersky GReAT.
Globally, in 2025, the top 3 categories of high-severity security incidents include Advanced Persistent Threats (APT) (24%), social engineering (15%), and malware (12%).
An APT is a highly sophisticated, targeted cyber campaign in which attackers gain unauthorised access to a network and maintain a covert presence over an extended period. These operations are typically conducted to facilitate cyber espionage, steal sensitive information, or achieve long-term strategic objectives. Kaspersky’s GReAT monitors more than 900 APT groups worldwide.
In terms of global APT landscape, five out of the top 12 most targeted countries are in APAC: China, India, Myanmar, Pakistan, and Vietnam.
“APAC as a global leader in digital transformation and even in AI agent adoption, coupled with its complex geopolitical environment, makes it a high-value target for threat actors behind the most advanced persistent threats. The concentration of targeted countries in the region underscores the strategic value of continuous threat intelligence, resilient cyber defenses, and stronger regional cooperation,” adds Lozhkin.
Global supply chain in danger
A recent Kaspersky study found that supply chain attacks have become one of the most common cyber threats facing businesses worldwide, with nearly one in three organisations experiencing a supply chain-related incident over the past year. China ranked among the countries with the highest exposure, with 40% of businesses reporting supply chain risks.
In one incident, attackers compromised eScan's antivirus update infrastructure, using the trusted update server to distribute malware to customers. By abusing legitimate software, the attackers turned a security product into an infection vector, highlighting the growing risks posed by co mpromised software supply chains. eScan is an antivirus and endpoint security software developed by Microworld Technologies, an Indian cybersecurity company headquartered in Mumbai.
Another notable case involved Notepad++, where a malicious installer delivered a Trojan backdoor that enabled attackers to maintain access to affected systems for months. The incident demonstrates how threat actors continue to exploit trusted applications to infiltrate enterprise environments while evading detection.
Notepad++ is a free, open-source text and source code editor for Windows. It is widely used by software developers, system administrators, IT professionals, and power users to write and edit code, scripts, configuration files, and plain text.
An active supply chain attack targeting the official website of Daemon Tools has also been underway since April 2026, according to Kasperksy GReAT. Daemon Tools is a disk image mounting and virtual drive emulation software for Windows.
By bundling malware with the legitimate software, attackers were able to remotely compromise infected devices. The campaign has impacted more than 2,000 victims across over 100 countries and territories, with the largest concentrations in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China.
The most headline-grabbing supply chain attack, by far, involves Axios, one of the most widely used JavaScript HTTP client libraries, with over 100 million weekly downloads on npm. In March 2026, attackers compromised the npm account of a lead Axios maintainer and used it to publish malicious versions of the package.
During Kaspersky GReAT analysis of the Axios supply chain attack, researchers identified technical overlaps with two BlueNoroff campaigns we had previously documented of: GhostCall and GhostHire.
BlueNoroff is a financially motivated subgroup of the Lazarus Group, known for targeting financial institutions and cryptocurrency platforms. The group has a long history of conducting sophisticated attacks aimed at stealing funds, often using social engineering and custom malware.
GhostCall and GhostHire are two BlueNoroff campaigns targeting high-value individuals in the crypto industry. While GhostCall uses sophisticated social engineering to target executives, GhostHire disguises malware as job opportunities and coding tests aimed at blockchain developers.
The overlaps include the use of a multi-platform attack framework targeting Windows, macOS, and Linux, similar Windows execution flow, recurring infrastructure, and distinctive malware artifacts such as the "webT" module name.
“We see a rising volume of threats targeting open-source software. In 2025, we detected 19,484 malicious packages, a 37% increase from 14,197 in 2024, while hacktool detections rose 11% year-on-year from 2,966 to 3,302. The findings underscore the growing need for organisations to strengthen software supply chain security as open-source components become increasingly integral to modern applications,” explains Lozhkin.
As supply chain attacks continue to grow in scale and sophistication, Kaspersky for its part, is strengthening its focus on securing the open-source software ecosystem. The company's Open-Source Software Threats Data Feed provides organisations with actionable intelligence on vulnerabilities (CVEs), malicious and compromised packages, as well as riskware and hacking tools, helping security teams identify threats early in the software development lifecycle.
To stay protected from sophisticated cyberattacks, organisations in APAC are advised to follow these best practices:
· To protect the company against a wide range of threats, use solutions from the Kaspersky Next product line that provide real-time protection, threat visibility, investigation and the response capabilities of EDR and XDR for organisations of any size and industry. Depending on your current needs and available resources, you can choose the most relevant product tier and easily migrate to another one if your cybersecurity requirements are changing.
· Adopt managed security services by Kaspersky such as Compromise Assessment, Managed Detection and Response (MDR) and / or Incident Response, covering the entire incident management cycle – from threat identification to continuous protection and remediation. They help to protect against evasive cyberattacks, investigate incidents and provide additional expertise even if a company lacks cybersecurity workers.
· Provide your InfoSec professionals with an in-depth visibility into cyberthreats targeting your organisation. The latest Kaspersky Threat Intelligence will provide them with rich and meaningful context across the entire incident management cycle and helps them identify cyber risks in a timely manner.
provide company leadership in anti-malware research and innovation, bringing unrivaled expertise, passion and curiosity to the discovery and analysis of cyberthreats.
Tracy