
India recorded 18,187 mobile threat detections in the first quarter of CY 2026, marking the highest number among Asia-Pacific markets tracked by Kaspersky's latest analysis. According to reports from Business Standard, Indonesia followed with 15,163 detections, while China recorded 6,797 cases. This positions India as the most targeted market in the region for mobile cyber threats, with the figures coming as mobile threats across APAC become increasingly concentrated.
The mobile threat landscape across APAC is becoming increasingly concentrated, with attackers adopting more targeted approaches. As reported by Business Standard, the average number of threat detections per affected user jumped 49% year-on-year in Q1 2026, rising from 4.9 to 7.3 detections per user. This increase occurred across all eight markets studied by Kaspersky, even as the total number of users encountering mobile threats actually declined. The findings are particularly relevant given how central smartphones have become in India, whether it's digital payments, social media, government services or shopping.
India's detection count is distinguished by malware campaigns specifically designed around Indian mobile user behavior patterns. According to Business Standard, Kaspersky flags two particularly active threats: the Rewardsteal Trojan, which poses as reward or giveaway apps to steal sensitive information, and the Thamera Trojan, which hijacks devices to create fraudulent social media accounts at scale. These campaigns exploit familiarity with services and habits that Indian users already trust, with the Thamera Trojan having made a comeback in recent activity.
Cybercriminals are expanding their reach beyond traditional email-based attacks to include messaging platforms, social media, and digital promotions. As reported by Business Standard, attackers are now spreading through text messages, messaging platforms, social media, fake job offers, and crypto giveaways. Compromised messaging accounts are particularly effective because malicious links appearing from trusted contacts appear far more credible than those from strangers. Kaspersky is seeing more scam activity built around fake promotions, phishing pages, malicious ads, fraudulent surveys and other social engineering tactics, with phishing remaining one of the most common methods.
Artificial intelligence is significantly complicating the detection of mobile threats through sophisticated social engineering tactics. According to Business Standard, Kaspersky's global study found that 66% of victims believed AI had been used against them in some form. AI-written messages represent the most common form at 42%, followed by generated or cloned voices at 31% and deepfake images or videos at 25%. The study also revealed that 52% of successful scams were completed in under 30 minutes from first contact to completion, with scammers using these tools to impersonate people victims already trust, including family members, and craft urgent, convincing requests for money or credentials.