Kaspersky’s Global Research and Analysis Team (GReAT) has reported that threat actors remained highly active across the Asia Pacific (APAC) region during the first half of 2026, with 250,000 ransomware attacks blocked between January and June.
According to data from the Kaspersky Security Network (KSN), analysed by GReAT, Kaspersky detected and blocked 75 million attacks originating from online resources across APAC during the six-month period. The data also recorded 3.4 million backdoor attacks and 2.4 million password-stealer attacks.
“While we observed slight declines in some attack categories during the first half of 2026, this should not be mistaken for a weakening threat landscape in the region. We are also monitoring that threat actors are increasingly leveraging AI to automate reconnaissance, accelerate malware development, and scale attacks, making them faster and more adaptive,” said Sergey Lozhkin, Head of APAC and META research units at Kaspersky GReAT.
Globally, Kaspersky identified Advanced Persistent Threats (APT), social engineering and malware as the top three categories of high-severity security incidents in 2025, accounting for 24%, 15% and 12%, respectively. Kaspersky’s GReAT monitors more than 900 APT groups worldwide.
Five of the 12 most targeted countries in the global APT landscape are in APAC: China, India, Myanmar, Pakistan and Vietnam.
“APAC as a global leader in digital transformation and even in AI agent adoption, coupled with its complex geopolitical environment, makes it a high-value target for threat actors behind the most advanced persistent threats. The concentration of targeted countries in the region underscores the strategic value of continuous threat intelligence, resilient cyber defences, and stronger regional cooperation,” Lozhkin added.
Global Supply Chain Risks Rise
Kaspersky also highlighted the growing threat posed by software supply-chain attacks. A recent Kaspersky study found that nearly one in three organisations globally experienced a supply-chain-related incident over the past year. China was among the countries with the highest exposure, with 40% of businesses reporting supply-chain risks.
One incident involved the compromise of eScan’s antivirus update infrastructure, which attackers used to distribute malware to customers through a trusted update server. Another case involved Notepad++, where a malicious installer delivered a Trojan backdoor that enabled attackers to maintain access to affected systems.
Kaspersky GReAT also reported an active supply-chain attack targeting the official Daemon Tools website since April 2026. According to the company, attackers bundled malware with legitimate software, affecting more than 2,000 victims across more than 100 countries and territories.
Another major incident involved Axios, a widely used JavaScript HTTP client library with more than 100 million weekly downloads on npm. In March 2026, attackers compromised the npm account of a lead Axios maintainer and used it to publish malicious versions of the package.
Kaspersky researchers identified technical overlaps between the Axios attack and two previously documented BlueNoroff campaigns, GhostCall and GhostHire. The overlaps included a multi-platform attack framework targeting Windows, macOS and Linux, similar Windows execution flows, recurring infrastructure and distinctive malware artefacts.
“We see a rising volume of threats targeting open-source software. In 2025, we detected 19,484 malicious packages, a 37% increase from 14,197 in 2024, while hacktool detections rose 11% year-on-year from 2,966 to 3,302,” said Lozhkin.
Kaspersky said the findings underline the need for organisations to strengthen software supply-chain security as open-source components become increasingly integral to modern applications. The company is also expanding its focus on the open-source software ecosystem through its open-source software threats data feed, which provides intelligence on vulnerabilities, malicious and compromised packages, riskware and hacking tools.
Kaspersky recommends that organisations strengthen real-time threat protection and visibility, adopt managed security services such as compromise assessment, managed detection and response and incident response, and provide security teams with deeper threat intelligence to identify and respond to cyber risks.