
According to Kaspersky's Global Research and Analysis Team (GReAT), India is among the five APAC countries most targeted by advanced persistent threats (APTs), highlighting the region's exposure to sophisticated cyber campaigns. The company monitors more than 900 APT groups globally, with five of the 12 countries most targeted by these groups located in APAC: China, India, Myanmar, Pakistan and Vietnam. As reported by Kaspersky GReAT, APAC as a global leader in digital transformation and even in AI agent adoption, coupled with its complex geopolitical environment, makes it a high-value target for threat actors behind the most advanced persistent threats. The findings come as Kaspersky blocked 75 million attacks from online resources across APAC in the first half of 2026, including 3.4 million backdoor attacks, 2.4 million password-stealer attacks and 250,000 ransomware incidents.
According to CloudSEK's recent report, cyber attackers are increasingly stealing AI access credentials and reselling compute through gray-market networks, raising financial and supply-chain risks for companies. The threat actor group TeamPCP orchestrated what is believed to be the largest supply chain attack, beginning in March 2026 and remaining active. As reported by CloudSEK, the stolen objects included cloud keys, repository tokens, SSH keys, Kubernetes secrets, package-publishing credentials, environment variables and AI provider keys, which could allow attackers to move far beyond the affected package. The company noted that a package can disappear in minutes while copied credentials remain usable for weeks or months unless they are rotated and downstream activity is investigated.
According to Kaspersky GReAT, threat actors are increasingly leveraging AI across different stages of their operations, using technology to automate reconnaissance, speed up malware development and scale attacks. The company detected 19,484 malicious packages in 2025, compared with 14,197 in 2024, marking a 37% increase, while hacktool detections also rose 11% year-on-year from 2,966 to 3,302. A notable example highlighted by Kaspersky involved Axios, a widely used JavaScript HTTP client library with more than 100 million weekly downloads on npm, where attackers compromised the npm account of a lead maintainer in March 2026 and used it to publish malicious versions. The company also identified technical overlaps with BlueNoroff campaigns, describing this subgroup as a financially motivated group targeting financial institutions and cryptocurrency platforms.
Kaspersky highlighted several major supply-chain incidents that demonstrate how attackers exploit trusted software and update mechanisms. In one case, attackers compromised the update infrastructure of eScan, an antivirus and endpoint security product developed by a Mumbai-based Indian cybersecurity company, using the trusted update server to distribute malware to customers. Another incident involved Notepad++, a free, open-source text and source-code editor, where a malicious installer delivered a Trojan backdoor allowing attackers to maintain access for months. The company also identified an active supply-chain attack targeting the official website of Daemon Tools that had been underway since April 2026, affecting more than 2,000 victims across more than 100 countries and territories. These incidents demonstrate how attackers can turn legitimate security software into infection vectors and compromise trusted software update mechanisms.
The shift toward AI-focused attacks represents a significant change in cybercriminal monetization strategies, with Cost Harvesting identified as the most common MITRE ATLAS Impact technique observed over the past year. As reported by CrowdStrike, Cost Harvesting is the most common MITRE ATLAS Impact technique observed over the past year, where attackers deliberately push victim AI services beyond normal usage to increase costs. The problem is compounded by the fact that AI services are increasingly tied directly to corporate cloud accounts, meaning compromised access can become a direct source of financial loss even without sensitive data theft. This creates a double-edged situation where AI serves as both a valuable corporate tool and an attractive target for cybercriminals, requiring organizations to balance innovation with enhanced security measures. According to Kaspersky, the combination of advanced persistent threats, AI-assisted attacks and growing supply-chain risks makes continuous threat intelligence and stronger cyber defences essential for organizations across APAC.