Kaspersky Reports 75 Million Attacks Blocked In APAC Region In First Half Of 2026

Low Boon Shen
5 Min Read

Kaspersky’s Global Research and Analysis Team (GReAT) reported that 75 million attacks originating from online resources were detected and blocked across the Asia-Pacific region during the first half of 2026. The findings found 3.4 million backdoor attacks, 2.4 million password stealer attacks and 250,000 ransomware incidents were prevented during the six-month period.

Kaspersky: Supply Chain Attacks Identified As Growing Global Threat

Kaspersky Reports 75 Million Attacks Blocked In APAC Region In First Half Of 2026
Kaspersky Reports 75 Million Attacks Blocked In APAC Region In First Half Of 2026

Sergey Lozhkin, Head of APAC and META research units at Kaspersky GReAT, said slight declines observed in some attack categories should not be interpreted as an overall weakening of the threat landscape, noting that threat actors are increasingly using AI to automate reconnaissance and accelerate malware development.

According to Kaspersky, the top three categories of high-severity security incidents recorded globally in 2025 were Advanced Persistent Threats (APT) at 24%, social engineering at 15%, and malware at 12%. Kaspersky’s GReAT monitors more than 900 APT groups worldwide, and the company noted that five of the twelve most targeted countries globally for APT activity are in APAC, namely China, India, Myanmar, Pakistan and Vietnam.

Lozhkin said APAC’s position as a region with advanced digital transformation and AI adoption, combined with its geopolitical complexity, makes it a target for advanced persistent threat groups, adding that this highlights the need for continuous threat intelligence and regional cybersecurity cooperation.

Kaspersky’s study found that supply chain attacks have become a common cyber threat facing businesses globally, with nearly one in three organisations reporting a supply chain-related incident over the past year. China was among the countries with the highest exposure, with 40% of businesses reporting supply chain risks.

Kaspersky cited several recent incidents, including an attack in which threat actors compromised the update infrastructure of eScan, an antivirus product developed by Indian cybersecurity company Microworld Technologies, using its trusted update server to distribute malware. A separate incident involved a malicious installer for Notepad++, a widely used text and code editor, which delivered a Trojan backdoor allowing attackers to maintain access to affected systems for extended periods.

The team also identified an ongoing supply chain attack targeting the official website of Daemon Tools, a disk image mounting software, active since April 2026. The campaign has affected more than 2,000 victims across over 100 countries, with the largest concentrations in Russia, Brazil, Turkey, Spain, Germany, France, Italy and China.

Kaspersky also referenced an attack in March 2026 involving Axios, a widely used JavaScript library with more than 100 million weekly downloads, in which attackers compromised the npm account of a lead maintainer to distribute malicious versions of the package. During its analysis of said incident, Kaspersky identified technical overlaps with two previously documented campaigns attributed to BlueNoroff, a financially-motivated subgroup of the Lazarus Group known for targeting financial institutions and cryptocurrency platforms.

The two campaigns, GhostCall and GhostHire, target individuals in the cryptocurrency industry, with GhostCall using social engineering to target executives and GhostHire disguising malware as job opportunities aimed at blockchain developers. According to Kaspersky, the overlaps included a shared multi-platform attack framework, similar execution flows on Windows systems, recurring infrastructure and shared malware artefacts.

Lozhkin said Kaspersky detected 19,484 malicious open-source packages in 2025, a 37% increase from 14,197 in 2024, while detections of hacking tools rose 11% year-on-year, from 2,966 to 3,302. In response to rising supply chain risks, Kaspersky said it is expanding its focus on securing open-source software through its Open-Source Software Threats Data Feed, which provides organizations with intelligence on vulnerabilities, malicious packages and hacking tools intended to help security teams identify threats earlier in the software development process.

Pokdepinion: I expect the number to become a lot worse next year now that AI is entering the equation.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *