250K Ransomware Attacks Blocked in APAC: Kaspersky GReAT
The cyber threat landscape across APAC remained highly active in the first half of 2026. Kaspersky detected and blocked 75 million attacks originating from online resources, including 3.4 million backdoor attacks, 2.4 million password stealer attacks and 250,000 ransomware incidents. The data comes from Kaspersky Security Network (KSN), analysed by Kaspersky GReAT.
“While we observed slight declines in some attack categories during the first half of 2026, this should not be mistaken for a weakening threat landscape in the region. We are also monitoring that threat actors are increasingly leveraging AI to automate reconnaissance, accelerate malware development, and scale attacks, making them faster and more adaptive,” says Sergey Lozhkin, Head of APAC and META research units at Kaspersky GReAT.
Globally, APTs accounted for 24% of high-severity security incidents in 2025, followed by social engineering (15%) and malware (12%). Kaspersky GReAT monitors more than 900 APT groups worldwide. Five of the 12 most targeted countries globally are in APAC: China, India, Myanmar, Pakistan and Vietnam.
“APAC as a global leader in digital transformation and even in AI agent adoption, coupled with its complex geopolitical environment, makes it a high-value target for threat actors behind the most advanced persistent threats. The concentration of targeted countries in the region underscores the strategic value of continuous threat intelligence, resilient cyber defenses, and stronger regional cooperation,” adds Lozhkin.
Supply chain attacks are also emerging as a major global concern, with nearly one in three organisations experiencing a supply chain-related incident over the past year. Notable incidents involving eScan, Notepad++, Daemon Tools and Axios demonstrated how attackers can exploit trusted software and open-source ecosystems to distribute malware and maintain access to victims. The Daemon Tools campaign alone affected more than 2,000 victims across over 100 countries and territories.
“We see a rising volume of threats targeting open-source software. In 2025, we detected 19,484 malicious packages, a 37% increase from 14,197 in 2024, while hacktool detections rose 11% year-on-year from 2,966 to 3,302. The findings underscore the growing need for organisations to strengthen software supply chain security as open-source components become increasingly integral to modern applications,” explains Lozhkin.
Kaspersky recommends organisations strengthen protection through endpoint, EDR and XDR solutions, managed security services such as MDR and Incident Response, and comprehensive threat intelligence to identify and respond to evolving cyber risks.