Cybersecurity firm Kaspersky said it blocked 75 million attacks originating from online resources in the Asia-Pacific region during the first half of 2026, highlighting the continued use of backdoors, credential-stealing malware, and ransomware against businesses and individuals.
Data from Kaspersky’s Global Research and Analysis Team showed that its systems detected more than 3.4 million backdoor attacks and 2.4 million password-stealer incidents across the region during the six-month period. Around 250,000 ransomware attacks were also blocked.
Kaspersky said slight declines in some categories should not be interpreted as an easing of cyber threats, as attackers are increasingly using artificial intelligence to accelerate reconnaissance, malware development, and the deployment of campaigns at scale.
Advanced persistent threats, or APTs, remained among the most serious security risks globally. These are typically prolonged and targeted campaigns in which attackers infiltrate networks to conduct espionage or steal information.
China, India, Myanmar, Pakistan, and Vietnam were among the Asia Pacific countries most frequently targeted by APT groups. Kaspersky attributed the level of activity to the region’s rapid digitalization and geopolitical significance.
Software supply chains have also become a major entry point for attackers. A Kaspersky study found that about one in three organizations worldwide encountered supply-chain-related attacks over the past year, with the incidence reaching 40% among surveyed businesses in China.
Recent incidents involved trusted software products and distribution channels. Attackers compromised the update infrastructure of antivirus provider eScan to deliver malware disguised as legitimate updates. A separate campaign used a malicious Notepad++ installer to place a backdoor on affected devices.
The official website of Daemon Tools was also compromised in a campaign that bundled malware with legitimate software. Kaspersky said the attack affected more than 2,000 victims in over 100 countries.
One of the most consequential incidents involved Axios, a widely used JavaScript library distributed through the npm software registry.
Attackers compromised the npm credentials of a lead maintainer in March and published two malicious Axios versions containing a dependency that installed a cross-platform remote-access Trojan. The packages were removed within hours.
Kaspersky said the incidents showed how attackers can use a single compromised developer account or software provider to distribute malware to potentially large numbers of downstream users.


