If you thought cybercriminals were taking a summer break, think again.
During the first half of 2026, threat actors stayed relentlessly active across the Asia-Pacific (APAC) region. According to new data from Kaspersky GReAT
(Global Research and Analysis Team), the company’s security systems thwarted a staggering 75 million online threats in APAC between January and June.
Among those blocked attacks were:
- 3.4 million backdoor attempts
- 2.4 million password stealers
- 250,000 ransomware attacks
While some attack categories saw slight numerical dips, experts warn against confusing lower numbers with a safer environment.
“Threat actors are increasingly leveraging AI to automate reconnaissance, accelerate malware development, and scale attacks, making them faster and more adaptive,” warns Sergey Lozhkin, Head of APAC and META research units at Kaspersky GReAT.
APAC Remains a Prime Target for Advanced Threats
APAC’s rapid digital transformation and early adoption of AI agents make it an attractive target. Out of the top 12 most targeted countries for Advanced Persistent Threats (APTs) globally, five are in APAC: China, India, Myanmar, Pakistan, and Vietnam.
Global APTs—which represent 24% of all high-severity security incidents—involve long-term, highly sophisticated campaigns where attackers stealthily slip into a network to conduct espionage or steal high-value data.
The Big Global Danger: Software Supply Chain Attacks
Beyond traditional malware, the real storm brewing right now involves software supply chain attacks. Nearly 1 in 3 organizations worldwide experienced a supply chain incident over the past year.
Instead of breaking down the front door of an enterprise, attackers are compromising the legitimate, trusted software tools businesses use every day.
High-Profile Supply Chain Victims Highlighted by GReAT:
- Axios (npm Package): In March 2026, attackers compromised the account of a lead maintainer for Axios—a JavaScript library with over 100 million weekly downloads—to distribute malicious versions. Kaspersky linked this to BlueNoroff, a financially motivated subgroup of the notorious Lazarus Group.
- Daemon Tools: An active campaign running since April 2026 bundled malware with official software downloads, impacting over 2,000 victims across 100+ countries.
- Notepad++: Attackers used a malicious installer to drop a Trojan backdoor into the popular open-source text editor, allowing them to lurk unnoticed inside systems for months.
- eScan: Cybercriminals compromised eScan’s antivirus update infrastructure, effectively turning a legitimate security product into a delivery vehicle for malware.
The threat inside open-source ecosystems is climbing fast. Malicious software package detections surged by 37% year-over-year, leaping to nearly 19,500 detected malicious packages.
How Organizations Can Stay Protected
To counter AI-driven reconnaissance and sneaky supply chain infiltrations, Kaspersky recommends a proactive, multi-layered approach:
- Deploy EDR and XDR Solutions: Implement modern Endpoint Detection and Response tools (like the Kaspersky Next lineup) to gain real-time visibility and fast remediation capabilities across your infrastructure.
- Leverage Managed Detection & Response (MDR): If in-house cybersecurity bandwidth is tight, utilize managed services for 24/7 threat hunting, compromise assessments, and expert-led incident response.
- Feed Your Team Live Threat Intelligence: Equip your InfoSec professionals with real-time threat intelligence feeds to spot open-source vulnerabilities (CVEs) and malicious dependencies early in the software development lifecycle.
Click Here For The Original Source.
