Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
From frontier policy to boardroom action: how enterprises should gover...
Dealing with agentic AI governance and resilience challenges
How can APAC enterprises face AI governance questions deftly? Key ques...
China-linked cyber espionage group shifts focus to another brand of ro...
Cohesity Delivers New Managed Clean Room Capability to Enhance HCLTech...
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      Dealing with agentic AI governance and resilience challenges

      Dealing with agentic AI governance and resilience challenges

      Thursday, September 3, 2026, 11:51 AM Asia/Singapore | Features
    • Featured

      How well do you know your agent?

      How well do you know your agent?

      Thursday, August 20, 2026, 3:21 PM Asia/Singapore | Features
    • Featured

      Bringing proof of identity to the digital economy

      Bringing proof of identity to the digital economy

      Wednesday, August 19, 2026, 10:50 AM Asia/Singapore | Features
  • Opinions
  • Tips
  • Whitepapers
  • AWARDS 2026
  • Directory
  • E-Learning

Select Page

Features

Asia Pacific’s unique cyberthreats

By Victor Ng | Monday, June 8, 2026, 5:04 PM Asia/Singapore

Asia Pacific’s unique cyberthreats

How different are APAC cyberthreats compared to those from other parts of the world? What does this uniqueness mean to organizations operating in the region?

We gathered key insights on the region’s threat landscape from Chase Li, Co-Founder, ThreatBook, as well as the differing approaches to cyber-attacks and cybersecurity from market to market within the region.

How different are APAC cyberthreats compared to those from other parts of the world? What does this uniqueness mean to organizations?

Li: There are multiple ways APAC-originated threats differ from those emanating from elsewhere. First is patience over speed. Advanced persistent threat (APT) groups from Asia typically operate on a different timeline to Western cybercriminals.

Whereas Western ransomware actors want quick monetization, Asian state-connected groups overwhelmingly dwell inside networks for months — and sometimes years — before executing their attacks. The objective is espionage, IP theft, and strategic intelligence gathering — not extortion.

This trend reflects a nuanced difference between this region and others: in the US for instance, almost half of all attacks involve ransomware; yet in Asia, only about one-quarter of all attacks are ransomware-related. In almost all instances, state-sponsored threats are part of an elaborate program, not an opportunistic attack.

A further point of difference is how Asian APT groups target tech supply chains. Their focus tends to be on regional telecoms vendors, managed service providers, and government contractors who act as pathways into primary targets. Such attacks are patient, indirect, and harder to detect than direct attacks.

In addition, the tactics, techniques and procedures (TTPs) used in Asia are built to evade Western detection logic. Most threat intelligence platforms available today are predominantly built on Western telemetry, and this has since led to structural blind spots.

Moreover, local groups specifically engineer their tradecraft to evade the detection models most enterprise tools rely on — using living-off-the-land techniques, legitimate tooling, and custom implants with no static signatures, among others.

A further point worth noting is how APAC cybercrime gangs are more rampant than their peers from elsewhere. One-third of all global attacks now occur within the region. Beyond nation-state actors, Asia has a thriving ecosystem of financially-motivated criminal groups targeting enterprises and ordinary citizens alike.

Silver Fox — a gang ThreatBook has tracked and named — is a prime example: a sophisticated threat group running large-scale fraud campaigns against businesses across Southeast Asia, deploying trojan software to compromise financial systems and harvest credentials from unsuspecting victims.

The implication for all organizations is clear: if your threat intelligence doesn’t have eyes on APAC-originated threats, you have significant blind spots.

What are some recent developments in the Dark Web that cyber-defenders should be concerned about?

Li: The initial access broker (IAB) market has professionalized — IABs specialize in gaining unauthorized access to target networks, and sell this access to other cybercriminals.

Corporate virtual private network (VPN) credentials, remote desktop protocol (RDP) endpoints, and single sign-on (SSO) tokens are typically auctioned before victim organizations know they have been breached.

There is now a liquid secondary market with pricing tiers, customer reviews, and escrow services. Some 71% of IAB listings today offer privileged access to compromised victims — enabling not just a foothold within target organizations, but full elevated permissions.

On top of this, infostealers have become the IAB market’s supply chain. Tools like LummaC2 and Vidar harvest credentials and multi-factor authentication (MFA) material from a single infected endpoint — on average, they harvest 87 stolen credentials per compromised device. Some 1.8 billion credentials were stolen via infostealers in the first half of 2025 alone.

The exposure window has shortened dramatically as well. Credentials harvested by infostealers are listed for sale within hours of theft. Organizations have a 24–72 hour window between credentials appearing on dark web markets and active exploitation. Post-breach detection systems are structurally too slow to cope with this timeline.

Meanwhile, Telegram has replaced dark web forums as the primary coordination platform for cybercriminal activity. As of March 2026, it is the most-used communication tool among threat actors. Unlike Tor-based forums that facilitate anonymous discussions on the dark web, Telegram channels can be recreated instantly, with subscriber bases redirected through forwarding links.

At the same time, nefarious Data-as-a-Service business models are emerging. Beyond one-time data dumps, some criminal groups now offer subscription access to continuously updated stolen enterprise data — with live intelligence feeds from compromised environments.

Impersonation can be deployed in real-time. The 2024 Hong Kong deepfake CFO case — where a finance employee transferred US$25M following a live video call with synthetic versions of known colleagues — demonstrated this capability is now operational, and not theoretical. Identity verification must move to out-of-band channels, and behavioral context that AI cannot replicate. Periodic callbacks, established code words, and second-channel confirmation must now be baseline controls for all high-value transactions.

Notably, the attack surface has shifted inward as well. Traditionally, social engineering attacks targeted network perimeters; today, by contrast, deepfake impersonations exploit relationships within organizations. The human layer is now the primary attack surface.

Why are previous detection and response solutions and strategies no longer effective? How should CISOs and their teams approach cybersecurity for today and the future?

Li: Most organizations haven’t yet defined what “effective” looks like. The right starting point is to set concrete operational goals — such as a dwell time, mean time to detect (MTTD), mean time to investigate (MTTI), and a mean time to respond (MTTR) — and work towards these. Without targets, tool selection and process design are guesswork.

However, the biggest hindrance to traditional detection and response is noise. Large numbers of false positives don’t just waste our time — they erode trust in the tooling, slow down decisions, and create conditions where real threats get lost. Noise reduction, accuracy improvement, and AI-driven investigation triage are thus the baseline requirement for any program that can keep pace with modern adversaries.

The traditional network perimeter no longer exists — yet the tooling still assumes it does. Cloud, remote work, third-party access, and supply chain exposure have dissolved the boundaries that most legacy architectures were designed to defend. Increasingly, adversaries aren’t breaking through walls — they’re walking in with keys.

Stolen credentials, compromised identities, and legitimate access paths are now the dominant initial vector. The detection model must account for this.

This new threat paradigm has made accuracy a vastly underrated metric. False positive rates are rarely the first thing evaluated in vendor selection — but they should be. Inaccurate intelligence feeds degrade every decision downstream: across analyst triage, automated responses, and escalation logic.

CISOs and their teams should therefore assume they have been breached, and are in a constant, compromised state. Preventing every intrusion is not a realistic goal. Security operations must be built on the assumption that adversaries will get in — and optimized for detecting and responding to attacks with precision.

They should set explicit targets and evaluate their tooling against them; while treating their false positive rates as a first-order operational metric that is also demanded of security vendors as well. CISOs and their teams must also ensure threat intelligence is embedded at every enforcement point, and not just piped into their security information and event management (SIEM) solution.

Ultimately, they must evaluate honestly whether their current tooling has genuine coverage of the threat actors most likely to target their sector and geography — and seek security solutions that make sizeable accuracy improvements, rather than assuming these can be made solely by additional headcount.

Share:

PreviousZero-day vulnerabilities expose AI agents to hijacking across enterprise messaging platforms
NextUhale Adopts Quokka’s Q-mast to Strengthen Application Security Testing

Related Posts

High stakes in the cybersecurity AI arms race

High stakes in the cybersecurity AI arms race

Tuesday, November 18, 2025

Time for a tough relook at laptop security and fitness for use

Time for a tough relook at laptop security and fitness for use

Thursday, November 28, 2019

The changing face of phishing scams

The changing face of phishing scams

Tuesday, October 8, 2019

Role of biometrics in mitigating security risks in Asia Pacific

Role of biometrics in mitigating security risks in Asia Pacific

Wednesday, August 11, 2021

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

PARTICIPATE NOW

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Cyber threats have become more frequent and sophisticated, targeting organizations of all sizes across all …Download Whitepaper
  • Zero Trust Made Simple: Why it matters and how to get started

    Zero Trust Made Simple: Why it matters and how to get started

    Data breaches and cyberattacks are no longer limited to large, high-profile organizations.Download Whitepaper
  • Cloud Secure Edge: Remote access, better security

    Cloud Secure Edge: Remote access, better security

    ​SonicWall Cloud Secure Edge™ is a modern, cloud-native Security Service Edge (SSE) solution that addresses …Download Whitepaper
  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your own digital infrastructure – including AI governance and cybersecurity – …Read more
  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more

Bottom sidebar

Other News

  • Cohesity Delivers New Managed Clean Room Capability to Enhance HCLTech VaultNXT

    Wednesday, September 2, 2026
    Cohesity Clean Room solution and …Read More »
  • Visa Launches Enhanced A2A Protect Innovations to Help Financial Institutions Stop Fraud Before Money Leaves Accounts

    Wednesday, September 2, 2026
    New unified fraud score is …Read More »
  • Malaysia’s Cybersecurity Leaders to Convene at the 34th Edition Cyber Security Summit Malaysia 2026

    Tuesday, September 1, 2026
    Summit to Bring Together More …Read More »
  • ICAC Commissioner in Vienna to meet new UNODC Chief to foster anti-corruption strategic collaboration and unveil ICAC’s AI enforcement system “Tianma” at UNODC’s anti-graft conference

    Tuesday, September 1, 2026
    VIENNA, Sept. 1, 2026 /PRNewswire/ …Read More »
  • Visa Expands Support for its Clients and the Industry as Organisations Navigate New AI Era of Cybersecurity

    Friday, August 28, 2026
    Latest Visa Vulnerability Agentic Harness release …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.