INTERPOL Asia & South Pacific Cyberthreat Assessment 2025/2026: Surging Phishing, Ransomware, and AI-Driven Scam-Center Fraud
INTERPOL Asia & South Pacific Cyberthreat Assessment (TL-2026-0897), also tracked as Asia and South Pacific Cyberthreat Assessment Report 2025/2026, is a high-severity tracked intrusion set, first published 2026-06-22. It is attributed to Southeast Asian transnational cybercrime syndicates with medium confidence, affects Cross-sector Real estate, manufacturing, and financial services, maps to 29 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-0897
- Threat ID
- TL-2026-0897
- Also known as
- Asia and South Pacific Cyberthreat Assessment Report 2025/2026, ASPJOC threat assessment, INTERPOL APAC cyberthreat assessment
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-06-22
- Last reviewed
- 2026-06-22
- Attribution
- Southeast Asian transnational cybercrime syndicates
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- real estate, manufacturing, financial services, consumers, government
- Target regions
- Asia, South Pacific, Southeast Asia, Oceania
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in INTERPOL Asia & South Pacific Cyberthreat Assessment
Malware and tooling: Agent Tesla, LokiBot, Lumma, RedLine, ZBot, Deepfake / synthetic media generation toolkits, Infostealer MaaS C2 over web protocols (HTTP/HTTPS)
INTERPOL's Asia and South Pacific Cyberthreat Assessment Report (2025/2026) documents a region-wide surge in phishing, ransomware, DDoS, and AI-driven fraud. Phishing is named the most widespread and financially damaging cybercrime, with 135,000+ ransomware attacks in 2024, DDoS up 92% year-over-year, system intrusions behind ~80% of data breaches, and transnational scam-center syndicates in Southeast Asia generating close to $40 billion annually using deepfakes and forced labor.
How INTERPOL Asia & South Pacific Cyberthreat Assessment works
INTERPOL's Asia and South Pacific Cyberthreat Assessment Report 2025/2026, covering January 2024 to March 2025, finds that cybercrime now accounts for at least 30% of all recorded crime in more than half of surveyed member countries, with more than 6.5 billion cyber threats detected and mitigated across the region during 2024.
Phishing is identified as the most widespread and financially damaging cybercrime in the region. A third (33%) of countries reported more than 10,000 phishing cases between January 2024 and March 2025, and 5.5 of every 1,000 individuals in the Asia and South Pacific region clicked on phishing links monthly — nearly double the global average of 2.9 per 1,000. Ransomware remains a dominant threat, with more than 135,000 ransomware-related attacks recorded in 2024, concentrated against the real estate, manufacturing, and financial services sectors. Distributed denial-of-service (DDoS) attacks surged 92% in 2024 compared with the previous year. System intrusions accounted for approximately 80% of all data breaches in 2024, with malware present in 83% of cases and ransomware in 51%.
The assessment names RedLine, Lumma, LokiBot, Negasteal (an Agent Tesla variant), and ZBot (Zeus) among the banking trojans and information-stealer families driving credential theft and follow-on fraud across the region. These commodity stealers harvest browser credentials, cookies, and session tokens, log keystrokes, and capture screens, feeding initial-access brokers and downstream ransomware and business-email-compromise operations.
A central finding is the industrialization of fraud by transnational organized-crime syndicates operating scam compounds in Cambodia, Laos, Myanmar, and the Philippines, frequently staffed by trafficked and forced labor. These operations blend AI personas and social engineering in 'romance baiting' (formerly 'pig butchering') investment-fraud schemes. Discussions about deepfakes on cybercriminal forums and messaging channels used by Southeast Asian threat actors increased 600% from February to June 2024, and regional scam-center operations are estimated to generate close to $40 billion annually (with $37 billion in regional cybercrime losses cited for the romance-baiting/deepfake nexus). INTERPOL coordinates the regional response through its Asia and South Pacific Joint Operations against Cybercrime (ASPJOC) framework. This record is a strategic threat-intelligence assessment rather than a single CVE; severity reflects the scale, active exploitation, and financial impact of the documented activity.
MITRE ATT&CK techniques used in TL-2026-0897
Collection
T1005 Data from Local System; T1113 Screen Capture
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1218 System Binary Proxy Execution; T1497 Virtualization/Sandbox Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol
Persistence
T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution
Credential Access
T1056 Input Capture; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer
Discovery
T1082 System Information Discovery; T1217 Browser Information Discovery; T1518 Software Discovery
Impact
T1486 Data Encrypted for Impact; T1498 Network Denial of Service; T1657 Financial Theft
Initial Access
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities
Reconnaissance
T1598 Phishing for Information
stealth
Affected products and versions in INTERPOL Asia & South Pacific Cyberthreat Assessment
- Cross-sector — Real estate, manufacturing, and financial services organizations (ransomware-targeted)
Vulnerable versions: Asia and South Pacific region - Cross-sector — Consumers and enterprises targeted by phishing and romance-baiting investment fraud
Vulnerable versions: Asia and South Pacific region
Remediation for INTERPOL Asia & South Pacific Cyberthreat Assessment
Immediate actions
- Deploy phishing-resistant MFA (FIDO2/WebAuthn) for email, banking, and remote access to blunt credential theft by RedLine/Lumma/LokiBot/ZBot stealers
- Block and monitor for known infostealer C2 over web protocols (HTTP/HTTPS) and inspect for credential/cookie exfiltration
- User awareness: flag romance-baiting/investment-fraud lures and deepfake executive-impersonation (voice/video) before fund transfers
Workarounds
- Disable macro execution and SmartScreen-bypass paths for email attachments (User Execution: Malicious File, T1204.002)
- Restrict execution of msiexec, mshta, and scripting interpreters from user-writable paths
Longer-term hardening
- Deploy EDR with behavioral detection for browser credential-store access (T1555.003) and web-session-cookie theft (T1539)
- Adopt callback verification / out-of-band approval for high-value financial transfers to counter deepfake business-email-compromise
- Continuous brand and credential-leak monitoring across stealer-log marketplaces
Timeline of INTERPOL Asia & South Pacific Cyberthreat Assessment
- Start of the INTERPOL assessment reporting period (January 2024 to March 2025).
- Deepfake discussions on cybercriminal forums begin a 600% increase running through June 2024 among Southeast Asian threat actors.
- Deepfake forum discussion volume reaches the 600% increase measured from February to June 2024.
- 2024 totals recorded: 135,000+ ransomware attacks, DDoS up 92% YoY, system intrusions behind ~80% of data breaches, malware present in 83% of breaches and ransomware in 51%, and 6.5B+ threats detected region-wide.
- INTERPOL releases new information on the globalization of scam centres, documenting expansion of Southeast Asian fraud operations beyond the region.
- End of the INTERPOL assessment reporting period; phishing cases exceed 10,000 in 33% of countries and phishing click rates reach 5.5 per 1,000 individuals monthly.
- INTERPOL publishes the Asia and South Pacific Cyberthreat Assessment Report 2025/2026 and a summary news release.
- Coverage details that regional scam-center networks generate close to $40 billion annually, with ~$37 billion in romance-baiting/deepfake-linked losses.
- The Hacker News and other outlets report INTERPOL's warning on rising phishing, ransomware, and AI-driven scams across Asia-Pacific.
Sources cited for INTERPOL Asia & South Pacific Cyberthreat Assessment
- INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific
- New INTERPOL report highlights escalating cyber threats across Asia and South Pacific
- INTERPOL Asia and South Pacific Cyber Threat Assessment Report 2025/2026 (PDF)
- Asia-Pacific scam networks generate nearly $40 billion a year
- INTERPOL report warns of rising cybercrime across Asia-Pacific
- INTERPOL releases new information on globalization of scam centres
- RedLine Stealer, Software S1240 — MITRE ATT&CK
- Lumma Stealer, Software S1213 — MITRE ATT&CK
- LokiBot, Software S0447 — MITRE ATT&CK
- Agent Tesla, Software S0331 — MITRE ATT&CK
- Zeus / Zbot, Software S0027 — MITRE ATT&CK
- Asia and South Pacific Joint Operations Against Cybercrime (ASPJOC)
Threats related to INTERPOL Asia & South Pacific Cyberthreat Assessment
Detection coverage for TL-2026-0897
As of 2026-06-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0897 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.