India Leads Asia-Pacific in Mobile Threat Detections, Report Finds
NEW DELHI – India has emerged as the most vulnerable market for mobile users across the Asia-Pacific (APAC) region, recording the highest number of cyber threat detections in the first quarter of 2026. According to a new report from cybersecurity giant Kaspersky, the country faced over 18,000 security incidents, underscoring the escalating risks posed by increasingly sophisticated digital adversaries.
The report, which analyzed data across eight APAC markets, identified India at the top of the list with 18,187 recorded mobile threat detections. It was followed closely by Indonesia, which recorded 15,163 incidents. Together, these two nations represent the highest volume of mobile security risks in the region.
The Rise of Stealthy Malware
Cybersecurity experts highlight that the nature of these attacks is shifting from broad, indiscriminate campaigns to more targeted and persistent efforts. India continues to be a primary target for malicious software such as the “Rewardsteal” Trojan. This specific threat cleverly disguises itself as legitimate reward or giveaway applications to gain access to, and subsequently harvest, sensitive user credentials.
Furthermore, researchers have identified a resurgence of the “Thamera” Trojan. This dangerous malware is capable of hijacking devices to create fraudulent social media accounts at scale, effectively turning compromised smartphones into tools for larger cyber-campaigns.
A Shift in Attack Strategy
Perhaps most alarming is the report’s finding regarding the frequency of these attacks. While the total number of individual users encountering threats has seen a decline, the number of threat detections per affected user has surged by 49% year-on-year, rising to 7.3 compared to 4.9 in the same period last year.
This data suggests a strategic pivot among cybercriminals: instead of casting a wide net, attackers are intensifying their efforts on specific targets, launching repeated assaults on individuals until they successfully breach their defenses.
Deception Through Digital Channels
The modern threat landscape is defined by psychological manipulation. Attackers are increasingly leveraging fake promotions, phishing pages, and fraudulent surveys to deceive users. These malicious links are being disseminated through a wide variety of channels, including:
- Messaging applications and SMS
- Social media platforms
- Deceptive job offers
- “Too good to be true” cryptocurrency investment schemes
Choon Hong Chee, head of the consumer channel for APAC at Kaspersky, emphasized the evolving nature of these risks. “Across APAC, mobile threats are becoming increasingly sophisticated, with cybercriminals combining stealthy attack techniques, persistent malware and AI-powered deception to target consumers,” Chee stated.
As the region grapples with this surge in digital risks, the report serves as a stark reminder for mobile users to remain vigilant against unsolicited messages and to exercise caution when engaging with promotional links or unverified applications. For a deeper dive into these findings, you can read the full report on mobile threat detections here.
