Search

Cookies

We use cookies to improve your experience. By continuing, you accept our use of cookies.

Technology

Mobile Cyber Threats Surge 49% in APAC; India Faces New AI-Powered Scams

· · 3 min read

Mobile threat detections surged 49% per user across the Asia-Pacific in Q1 2026, with India recording 18,187 incidents. Cybercriminals now leverage AI, malicious apps, and sophisticated phishing tactics via messaging and fake offers, making threats increasingly difficult to identify.

Mobile users across the Asia-Pacific (APAC) region are confronting a sharp rise in sophisticated cyber threats, with detections per affected user jumping 49% in the first quarter of 2026. This increase, reported by Kaspersky, saw the average number of detections climb from 4.9 to 7.3 per user, even as the total number of affected individuals slightly decreased.

India a Major Target for Mobile Cyber Threats

India stands as one of the region's most active targets, recording 18,187 mobile threat detections during the quarter. This significant volume underscores the expanding landscape of mobile-first services and smartphone adoption across the country.

For Indian consumers, specific threats remain particularly active:

  • Rewardsteal Trojan: This malware masquerades as reward or giveaway applications, designed to steal sensitive personal information from unsuspecting users.
  • Thamera Trojan: Resurfacing as a major threat, Thamera can hijack devices to create fraudulent social media accounts on a massive scale, impacting both individuals and platforms.

Evolving Tactics: Beyond Traditional Email Scams

Cybercriminals are increasingly moving beyond conventional email-based phishing. Malicious links are now widely distributed through a variety of channels, including:

  • Text messages (SMS)
  • Messaging applications
  • Social media platforms
  • Fake job offers
  • Cryptocurrency giveaways
  • Digital promotions

Attackers also employ sophisticated techniques like fake domains, typosquatting, and convincing imitations of trusted brands to trick users into divulging credentials and personal data. Compromised messaging accounts are particularly dangerous, as malicious links can appear to originate from a known and trusted contact, increasing the likelihood of a click.

AI's Role in Heightening Deception

Artificial intelligence (AI) is adding a new layer of complexity and believability to these scams. A Kaspersky study revealed that 66% of scam victims suspected AI was used against them. This includes AI-generated messages, cloned voices, and deepfake images or videos, making fraudulent communications much harder to distinguish from legitimate ones. Disturbingly, more than half of successful scams analyzed were completed in under 30 minutes, highlighting the speed and efficacy of these new methods.

Choon Hong Chee, Head of Consumer Channel for APAC at Kaspersky, emphasized, “Across APAC, mobile threats are becoming increasingly sophisticated, with cybercriminals combining stealthy attack techniques, persistent malware and AI-powered deception to target consumers. As scams become more convincing and harder to spot, staying protected requires security that can detect threats proactively, even before users realise they are under attack.”

How Consumers Can Protect Themselves

As threats evolve, proactive consumer vigilance is paramount. Kaspersky advises several key protective measures:

  • Verify Apps: Always confirm the legitimacy of applications before downloading them, ensuring they come from official app stores.
  • Caution with Offers: Be highly suspicious of "free reward" or cashback offers that seem too good to be true.
  • Review Permissions: Carefully examine the permissions requested by apps before granting them access to your device's data or functions.
  • Enable Multi-Factor Authentication (MFA): Implement MFA for all online accounts to add an extra layer of security beyond just a password.
  • Verify Links: Always double-check links received via messages and social media before clicking, looking for suspicious URLs or typos.
  • Keep Software Updated: Regularly update your operating system and all applications to patch known vulnerabilities.

The message for smartphone users is clear: digital services are indispensable, but using them with extreme caution and verification is essential to protect personal information, accounts, and financial security.

Related