APAC Threat Landscape Report, August 2026
← Research Hub

APAC Threat Landscape Report, August 2026

696 threats across the region in August 2026, and Group-IB’s APAC Threat Landscape Report names the groups targeting organisations and businesses in Asia-Pacific (APAC) - and what they’ll do next.

What is the Group-IB APAC Threat Landscape Report?

Group-IB’s monthly threat intelligence report on the cybercriminal, hacktivist and nation-state activity targeting Asia-Pacific between 1 to 31 August 2026. This month’s edition documents 695 threat incidents: 583 data leaks, 190 ransomware events, and 118 hacktivism operations – all sourced entirely from Group-IB’s own intelligence collection.

Synopsis

Asia-Pacific is where the world’s fastest digital growth meets the world’s busiest threat actors.

 

In August 2026, Group-IB tracked 695 threat reports across the region. Data leaks increased, ransomware surged, and a state-sponsored zero-day campaign quietly ran through the software South Koreans are required to install for local banking services.

 

India bore the brunt with 182 incidents, followed by Indonesia, China, and Japan. Government and military stayed the most-targeted sector.

 

Every figure here comes from Group-IB’s own collection. It’s written for defenders who need to prioritise, not just observe.

Key Threat Intelligence Findings and Insights in August 2026

Ransomware jumped 26.7% in a single monthRansomware jumped 26.7% in a single month

Group-IB recorded 190 ransomware attacks across APAC in August 2026, up 26.7% from July 2026. The Gentlemen, Krybit, and Qilin led; with The Gentlemen alone claiming 37 leak events.

Operation Double Barrel weaponised the software South Koreans trust.Operation Double Barrel weaponised the software South Koreans trust.

A state-sponsored campaign exploited zero-day flaws in the financial-security software South Korean users must install to access banking and institutional services - chaining watering-hole and spear-phishing lures across legitimate Korean media, education, and healthcare sites to plant backdoors.

Krybit came out of nowhere and tripled overnight.Krybit came out of nowhere and tripled overnight.

August's Adversary of the Month grew its output 230% month-on-month from 10 events to 33, running a dedicated leak site with healthcare firmly in its sights.

Manufacturing was the region's most-hit sector.Manufacturing was the region's most-hit sector.

Manufacturing led with 38 ransomware events - ahead of real estate and healthcare - including a Cl0p zero-day campaign (CVE-2026-12569) that stole engineering data across Taiwan, China, India, and Australia.

Pro-Russian hacktivism arrived in APAC at scale.Pro-Russian hacktivism arrived in APAC at scale.

NoName057(16) launched its first sustained regional campaign with 21 DDoS attacks on Japan; while Z-Pentest and allied groups claimed hands-on access to operational-technology systems in South Korea and Bangladesh.

23 million records, allegedly from Chinese banks.23 million records, allegedly from Chinese banks.

Threat actor Blastoize advertised the trove across underground forums. Group-IB's sample analysis flagged several indicators that warrant caution - the kind of verification a raw feed never gives you.

Nation-state espionage targeted India and Bangladesh defence.Nation-state espionage targeted India and Bangladesh defence.

Transparent Tribe (APT36) delivered CrimsonRAT to India's National Highways Authority, while a separate operation used remote template injection to hit Bangladesh's military with malware that was engineered to pass static scanning.

A stealer thought dead grew 50%.A stealer thought dead grew 50%.

While the overall compromised-account volume fell, LummaC2 rose 50% month-on-month - a reminder that in the infostealer market, brands rarely die.

Who Must Read This Report

CISOs and security leaders across APAC who prioritise defensive investment against the threats actually hitting the region.CISOs and security leaders across APAC who prioritise defensive investment against the threats actually hitting the region.

SOC and threat intelligence teams who need current tactics, techniques, and procedures (TTPs) mapped to MITRE ATT&CK.SOC and threat intelligence teams who need current tactics, techniques, and procedures (TTPs) mapped to MITRE ATT&CK.

Fraud and financial-crime teams at banks, fintechs, and payment providers tracking bank-card compromise, stealer logs, and large scale data-sale claims.Fraud and financial-crime teams at banks, fintechs, and payment providers tracking bank-card compromise, stealer logs, and large scale data-sale claims.

Government and critical infrastructure operators assessing nation-state and OT-focused hacktivist activity.Government and critical infrastructure operators assessing nation-state and OT-focused hacktivist activity.

Risk, compliance, and board stakeholders who need an evidence-based read on regional cyber risk and its regulatory implications.Risk, compliance, and board stakeholders who need an evidence-based read on regional cyber risk and its regulatory implications.

Know who's targeting your region before they reach your network.

Named groups. Named sectors. Hard numbers. All sourced from Group-IB Threat Intelligence.

Frequently asked questions

How many cyber threats did Group-IB track in APAC in August 2026?

arrow_drop_down

Group-IB documented 695 threat reports across Asia-Pacific in August 2026: 583 data leaks, 190 ransomware events, and 118 hacktivism operations.

Who was the most active ransomware group in APAC in August 2026?

arrow_drop_down

The Gentlemen was the most active, claiming 37 of the region’s ransomware leak events, followed by Krybit and Qilin. Total ransomware activity rose 26.7% month-on-month.

What was Operation Double Barrel?

arrow_drop_down

Operation Double Barrel was a state-sponsored campaign exploiting zero-day vulnerabilities in the financial-security software South Korean users must install for banking and institutional access, using watering-hole and spear-phishing lures across legitimate Korean websites to deploy backdoor malware.

Which APAC countries were most targeted in August 2026?

arrow_drop_down

India was most targeted, followed by Indonesia, China, and Japan.

Who is Krybit?

arrow_drop_down

Krybit is a ransomware and data-leak-extortion group first observed by Group-IB in April 2026. In August, it recorded a 230% month-on-month increase in events across eight APAC countries, with healthcare a signature target.

Is the report free to download?

arrow_drop_down

Yes. The August 2026 APAC Threat Landscape is a free download via the form on this page.