Security
Mobile Threats in APAC Grow More Targeted as Detections Per User Rise 49%, Kaspersky Finds
2026-08-25
Mobile threat activity in Asia-Pacific is becoming more concentrated, with attackers focusing on a smaller pool of users and targeting each of them far more persistently, according to Kaspersky. The company said cybercriminals are increasingly adapting campaigns to local user behavior, popular digital services and rapidly expanding mobile-first economies.
Across eight APAC markets, the average number of mobile threat detections per affected user rose 49% year-on-year in the first quarter of 2026, climbing from 4.9 to 7.3, Kaspersky said. The firm said the increase was recorded in every market analyzed, even as the total number of users encountering mobile threats declined overall.
Sharpest concentration seen in Thailand and Sri Lanka
Thailand recorded the sharpest concentration in Southeast Asia, according to Kaspersky, with detections more than doubling to 2,494 while the number of affected users fell, lifting detections per user from 3.0 to 11.9. Sri Lanka recorded 922 detections, up 132% year-on-year, the firm said, with detections per user rising from 5.5 to 17.4.
Detections in the Philippines rose 28% to 2,011, and in Bangladesh 108% to 1,859, according to Kaspersky. China recorded 6,797 detections, almost double the same period in 2025, and was one of only two markets — alongside Bangladesh — where both total detections and affected users increased, the firm said. India and Indonesia remained the region's largest markets by volume, with 18,187 and 15,163 detections respectively, according to Kaspersky.
Scams increasingly rely on social engineering and AI
Kaspersky said researchers observed a growing volume of mobile scam activity leveraging fake promotions, phishing pages, malicious advertising, fraudulent surveys and other social engineering techniques designed to trick users into revealing credentials or personal information. Phishing links remain one of the most common tools, the firm said, luring users to fraudulent websites through fake domains, typosquatting and convincing copies of trusted brands.
Malicious links are now distributed well beyond email, according to Kaspersky, spreading through text messages, messaging apps, social media, fake job offers, cryptocurrency giveaways and digital promotions. The firm said messaging platforms are a growing target, with compromised accounts increasingly abused to spread malicious links that appear to come from trusted contacts, and that credentials for messaging platforms and government service portals are especially prized since access can enable identity theft and broader compromise of victims' digital lives.
Attack techniques are growing more sophisticated, Kaspersky said, with some users exposed to malicious content simply by visiting a compromised webpage, requiring little or no interaction. Multi-stage attack chains that begin with seemingly harmless files, links or messages continue to make threats harder to identify and block, according to the firm. India continues to face the Rewardsteal Trojan, which disguises itself as reward or giveaway apps to steal sensitive data, alongside a resurgence of the Thamera Trojan, which hijacks devices to create fraudulent social media accounts at scale, Kaspersky said.
AI is making mobile scams more convincing and harder to detect, according to Kaspersky. Separate global consumer research by the firm, titled "The Great Messaging Heist," found that two-thirds of victims, or 66%, believe AI was used against them, most commonly through AI-written messages at 42%, followed by generated or cloned voices at 31% and deepfake images or video at 25%. The same research found that more than half of successful scams, or 52%, run their course in under 30 minutes, from first contact to the point where money or personal data changes hands.
Choon Hong Chee, head of consumer channel for APAC at Kaspersky, said the growing sophistication demands more proactive defenses. "Across APAC, mobile threats are becoming increasingly sophisticated, with cybercriminals combining stealthy attack techniques, persistent malware and AI-powered deception to target consumers," he said. "As scams become more convincing and harder to spot, staying protected requires security that can detect threats proactively, even before users realise they are under attack."
Across eight APAC markets, the average number of mobile threat detections per affected user rose 49% year-on-year in the first quarter of 2026, climbing from 4.9 to 7.3, Kaspersky said. The firm said the increase was recorded in every market analyzed, even as the total number of users encountering mobile threats declined overall.
Sharpest concentration seen in Thailand and Sri Lanka
Thailand recorded the sharpest concentration in Southeast Asia, according to Kaspersky, with detections more than doubling to 2,494 while the number of affected users fell, lifting detections per user from 3.0 to 11.9. Sri Lanka recorded 922 detections, up 132% year-on-year, the firm said, with detections per user rising from 5.5 to 17.4.
Detections in the Philippines rose 28% to 2,011, and in Bangladesh 108% to 1,859, according to Kaspersky. China recorded 6,797 detections, almost double the same period in 2025, and was one of only two markets — alongside Bangladesh — where both total detections and affected users increased, the firm said. India and Indonesia remained the region's largest markets by volume, with 18,187 and 15,163 detections respectively, according to Kaspersky.
Scams increasingly rely on social engineering and AI
Kaspersky said researchers observed a growing volume of mobile scam activity leveraging fake promotions, phishing pages, malicious advertising, fraudulent surveys and other social engineering techniques designed to trick users into revealing credentials or personal information. Phishing links remain one of the most common tools, the firm said, luring users to fraudulent websites through fake domains, typosquatting and convincing copies of trusted brands.
Malicious links are now distributed well beyond email, according to Kaspersky, spreading through text messages, messaging apps, social media, fake job offers, cryptocurrency giveaways and digital promotions. The firm said messaging platforms are a growing target, with compromised accounts increasingly abused to spread malicious links that appear to come from trusted contacts, and that credentials for messaging platforms and government service portals are especially prized since access can enable identity theft and broader compromise of victims' digital lives.
Attack techniques are growing more sophisticated, Kaspersky said, with some users exposed to malicious content simply by visiting a compromised webpage, requiring little or no interaction. Multi-stage attack chains that begin with seemingly harmless files, links or messages continue to make threats harder to identify and block, according to the firm. India continues to face the Rewardsteal Trojan, which disguises itself as reward or giveaway apps to steal sensitive data, alongside a resurgence of the Thamera Trojan, which hijacks devices to create fraudulent social media accounts at scale, Kaspersky said.
AI is making mobile scams more convincing and harder to detect, according to Kaspersky. Separate global consumer research by the firm, titled "The Great Messaging Heist," found that two-thirds of victims, or 66%, believe AI was used against them, most commonly through AI-written messages at 42%, followed by generated or cloned voices at 31% and deepfake images or video at 25%. The same research found that more than half of successful scams, or 52%, run their course in under 30 minutes, from first contact to the point where money or personal data changes hands.
Choon Hong Chee, head of consumer channel for APAC at Kaspersky, said the growing sophistication demands more proactive defenses. "Across APAC, mobile threats are becoming increasingly sophisticated, with cybercriminals combining stealthy attack techniques, persistent malware and AI-powered deception to target consumers," he said. "As scams become more convincing and harder to spot, staying protected requires security that can detect threats proactively, even before users realise they are under attack."
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




