Download the full APAC Intelligence Insights Report – December 2025 to access proprietary data and strategic recommendations for securing your organization in the new year.
The APAC region is experiencing unprecedented digital acceleration, positioning it as a primary target for sophisticated organized threat groups and nation-state actors.
This report provides the clarity needed to:
Decipher Regional Evolution
Understand how cyber threats are maturing across the region.
Identify High-Risk Sectors
Pinpoint the industries and geographies facing the highest volume of localized attacks.
Anticipate 2026 Tactics
Gain early visibility into emerging “Stranger Threats”, including agentic extortion and AI-powered malware.
Operationalize Defense
Convert raw intelligence into practical, defensive decisions to safeguard critical infrastructure and corporate assets.
Massive Escalation in Malicious Activity
The final month of 2025 saw a staggering 1,107% increase in compromised bank cards and a 376% surge in compromised accounts.
The Return of LockBit
Ransomware activity rose by 16% this month, with the LockBit group resurfacing to target Manufacturing, Professional Services and Real Estate sectors in India, Thailand and Malaysia.
Geopolitical Hacktivism
Political friction between Cambodia and Thailand triggered a 161% increase in DDos and Hacktivisim. The actor KXICIXXSEC specifically targeted Thai government and educational infrastructure, leading to a 9x increase in regional volume.
AI-Enhanced Adversary Operations
Advanced Persistent Threat (APT) groups like APT42 are now leveraging Large Language Models (LLMs) to automate intelligence processing and refine spear-phishing lures, significantly increasing the success rate of social engineering.
GoldFactory’s Banking “Goldmines”
Group-IB has identified over 300 unique samples of modified banking applications used by the GoldFactory group. With 11,000+ infections, this campaign uses experimental OCR and QR scanning to hijack mobile banking on both iOS and Android.
Zero-Day & Vulnerability Exploitation
Technical analysis of the React2Shell (CVE-2025-55182) vulnerability reveals how adversaries are rapidly weaponizing new exploits to gain remote code execution in regional environments.
This intelligence briefing is designed for professionals responsible for maintaining the integrity and resilience of APAC-based operations: