Kaspersky records rising mobile malware activity across Asia-Pacific markets

Mobile threat activity in Asia-Pacific is becoming more concentrated, with attackers focusing on a smaller pool of users and targeting each of them far more persistently, according to the latest data from Kaspersky. Cybercriminals are increasingly adapting their campaigns to local user behavior, popular digital services, and rapidly expanding mobile-first economies.

Across eight APAC markets, the average number of mobile threat detections per affected user rose 49% year-on-year in the first quarter of 2026, climbing from 4.9 to 7.3. The increase was recorded in every market analyzed, even as the total number of users encountering mobile threats declined.

Key findings from the first quarter of 2026:

  • Detections per affected user rose in all eight markets analyzed, indicating more persistent targeting of individual users.
  • Thailand recorded the sharpest concentration in Southeast Asia, with detections more than doubling to 2,494 while the number of affected users fell — lifting detections per user from 3.0 to 11.9.
  • Sri Lanka recorded 922 detections, up 132% year-on-year, with detections per user rising from 5.5 to 17.4.
  • Detections in the Philippines rose 28% to 2,011, and in Bangladesh 108% to 1,859.
  • China recorded 6,797 detections, almost double the same period in 2025.
  • China and Bangladesh were the only markets where both detections and affected users increased.
  • India and Indonesia remain the region’s largest markets by volume, with 18,187 and 15,163 detections respectively.

Researchers also observed a growing volume of mobile scam activity leveraging fake promotions, phishing pages, malicious advertising, fraudulent surveys, and other social engineering techniques designed to trick users into revealing credentials or personal information. Phishing links remain one of the most common tools, luring users to fraudulent websites through fake domains, typosquatting, and convincing copies of trusted brands.

Malicious links are now distributed well beyond email, through text messages, messaging apps, social media, fake job offers, cryptocurrency giveaways, and digital promotions. Messaging platforms are a growing target, with compromised accounts increasingly abused to spread malicious links that appear to come from trusted contacts. Credentials for messaging platforms and government service portals are especially prized, as access can enable identity theft, fraud, and broader compromise of victims’ digital lives.

Attack techniques are growing more sophisticated: some users are exposed to malicious content simply by visiting a compromised webpage, requiring little or no interaction. Multi-stage attack chains, starting with seemingly harmless files, links, or messages — continue to make threats harder to identify and block.

Malware families remain active in the region as well. India continues to face the Rewardsteal Trojan, which disguises itself as reward or giveaway apps to steal sensitive data, alongside the resurgence of the Thamera Trojan, which hijacks devices to create fraudulent social media accounts at scale.

Artificial intelligence (AI) is making mobile scams more convincing and harder to detect. Separate global Kaspersky consumer research into messaging-app fraud, The Great Messaging Heist, found that two-thirds of victims (66%) believe AI was used against them — most commonly in AI-written messages (42%), followed by generated or cloned voices (31%) and deepfake images or video (25%). Scammers use these tools to impersonate trusted contacts, including family members, and to pressure victims into urgent money transfers or credential disclosure. The same research found that more than half of successful scams (52%) run their course in under 30 minutes, from first contact to the point where money or personal data changes hands.

“Across APAC, mobile threats are becoming increasingly sophisticated, with cybercriminals combining stealthy attack techniques, persistent malware and AI-powered deception to target consumers. As scams become more convincing and harder to spot, staying protected requires security that can detect threats proactively, even before users realise they are under attack,”said Choon Hong Chee, Head of Consumer Channel for APAC at Kaspersky.

Kaspersky advises users to:

  • Verify app legitimacy before downloading;
  • Be cautious of “free reward” or “cashback” offers;
  • Review app permissions carefully;
  • Enable multi-factor authentication wherever possible;
  • Carefully verify links received through messages, emails, and social media platforms;
  • Keep operating systems and applications updated;
  • Use trusted mobile cybersecurity solutions for continuous protection.

Author