INTERPOL Asia & South Pacific Cyberthreat Assessment 2025/2026: Surging Phishing, Ransomware, and AI-Driven Scam-Center Fraud

INTERPOL Asia & South Pacific Cyberthreat Assessment (TL-2026-0897), also tracked as Asia and South Pacific Cyberthreat Assessment Report 2025/2026, is a high-severity tracked intrusion set, first published 2026-06-22. It is attributed to Southeast Asian transnational cybercrime syndicates with medium confidence, affects Cross-sector Real estate, manufacturing, and financial services, maps to 29 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 21 indicators of compromise.

Key facts for TL-2026-0897

Threat ID
TL-2026-0897
Also known as
Asia and South Pacific Cyberthreat Assessment Report 2025/2026, ASPJOC threat assessment, INTERPOL APAC cyberthreat assessment
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-06-22
Last reviewed
2026-06-22
Attribution
Southeast Asian transnational cybercrime syndicates
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
real estate, manufacturing, financial services, consumers, government
Target regions
Asia, South Pacific, Southeast Asia, Oceania
Detection rules
9
Indicators of compromise
21

Malware and tooling in INTERPOL Asia & South Pacific Cyberthreat Assessment

Malware and tooling: Agent Tesla, LokiBot, Lumma, RedLine, ZBot, Deepfake / synthetic media generation toolkits, Infostealer MaaS C2 over web protocols (HTTP/HTTPS)

INTERPOL's Asia and South Pacific Cyberthreat Assessment Report (2025/2026) documents a region-wide surge in phishing, ransomware, DDoS, and AI-driven fraud. Phishing is named the most widespread and financially damaging cybercrime, with 135,000+ ransomware attacks in 2024, DDoS up 92% year-over-year, system intrusions behind ~80% of data breaches, and transnational scam-center syndicates in Southeast Asia generating close to $40 billion annually using deepfakes and forced labor.

How INTERPOL Asia & South Pacific Cyberthreat Assessment works

INTERPOL's Asia and South Pacific Cyberthreat Assessment Report 2025/2026, covering January 2024 to March 2025, finds that cybercrime now accounts for at least 30% of all recorded crime in more than half of surveyed member countries, with more than 6.5 billion cyber threats detected and mitigated across the region during 2024.

Phishing is identified as the most widespread and financially damaging cybercrime in the region. A third (33%) of countries reported more than 10,000 phishing cases between January 2024 and March 2025, and 5.5 of every 1,000 individuals in the Asia and South Pacific region clicked on phishing links monthly — nearly double the global average of 2.9 per 1,000. Ransomware remains a dominant threat, with more than 135,000 ransomware-related attacks recorded in 2024, concentrated against the real estate, manufacturing, and financial services sectors. Distributed denial-of-service (DDoS) attacks surged 92% in 2024 compared with the previous year. System intrusions accounted for approximately 80% of all data breaches in 2024, with malware present in 83% of cases and ransomware in 51%.

The assessment names RedLine, Lumma, LokiBot, Negasteal (an Agent Tesla variant), and ZBot (Zeus) among the banking trojans and information-stealer families driving credential theft and follow-on fraud across the region. These commodity stealers harvest browser credentials, cookies, and session tokens, log keystrokes, and capture screens, feeding initial-access brokers and downstream ransomware and business-email-compromise operations.

A central finding is the industrialization of fraud by transnational organized-crime syndicates operating scam compounds in Cambodia, Laos, Myanmar, and the Philippines, frequently staffed by trafficked and forced labor. These operations blend AI personas and social engineering in 'romance baiting' (formerly 'pig butchering') investment-fraud schemes. Discussions about deepfakes on cybercriminal forums and messaging channels used by Southeast Asian threat actors increased 600% from February to June 2024, and regional scam-center operations are estimated to generate close to $40 billion annually (with $37 billion in regional cybercrime losses cited for the romance-baiting/deepfake nexus). INTERPOL coordinates the regional response through its Asia and South Pacific Joint Operations against Cybercrime (ASPJOC) framework. This record is a strategic threat-intelligence assessment rather than a single CVE; severity reflects the scale, active exploitation, and financial impact of the documented activity.

MITRE ATT&CK techniques used in TL-2026-0897

Collection

T1005 Data from Local System; T1113 Screen Capture

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1218 System Binary Proxy Execution; T1497 Virtualization/Sandbox Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol

Persistence

T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution

Credential Access

T1056 Input Capture; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

Discovery

T1082 System Information Discovery; T1217 Browser Information Discovery; T1518 Software Discovery

Impact

T1486 Data Encrypted for Impact; T1498 Network Denial of Service; T1657 Financial Theft

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities

Reconnaissance

T1598 Phishing for Information

stealth

T1684.001 Impersonation

Affected products and versions in INTERPOL Asia & South Pacific Cyberthreat Assessment

  • Cross-sector — Real estate, manufacturing, and financial services organizations (ransomware-targeted)
    Vulnerable versions: Asia and South Pacific region
  • Cross-sector — Consumers and enterprises targeted by phishing and romance-baiting investment fraud
    Vulnerable versions: Asia and South Pacific region

Remediation for INTERPOL Asia & South Pacific Cyberthreat Assessment

Immediate actions

  • Deploy phishing-resistant MFA (FIDO2/WebAuthn) for email, banking, and remote access to blunt credential theft by RedLine/Lumma/LokiBot/ZBot stealers
  • Block and monitor for known infostealer C2 over web protocols (HTTP/HTTPS) and inspect for credential/cookie exfiltration
  • User awareness: flag romance-baiting/investment-fraud lures and deepfake executive-impersonation (voice/video) before fund transfers

Workarounds

  • Disable macro execution and SmartScreen-bypass paths for email attachments (User Execution: Malicious File, T1204.002)
  • Restrict execution of msiexec, mshta, and scripting interpreters from user-writable paths

Longer-term hardening

  • Deploy EDR with behavioral detection for browser credential-store access (T1555.003) and web-session-cookie theft (T1539)
  • Adopt callback verification / out-of-band approval for high-value financial transfers to counter deepfake business-email-compromise
  • Continuous brand and credential-leak monitoring across stealer-log marketplaces

Timeline of INTERPOL Asia & South Pacific Cyberthreat Assessment

  • Start of the INTERPOL assessment reporting period (January 2024 to March 2025).
  • Deepfake discussions on cybercriminal forums begin a 600% increase running through June 2024 among Southeast Asian threat actors.
  • Deepfake forum discussion volume reaches the 600% increase measured from February to June 2024.
  • 2024 totals recorded: 135,000+ ransomware attacks, DDoS up 92% YoY, system intrusions behind ~80% of data breaches, malware present in 83% of breaches and ransomware in 51%, and 6.5B+ threats detected region-wide.
  • INTERPOL releases new information on the globalization of scam centres, documenting expansion of Southeast Asian fraud operations beyond the region.
  • End of the INTERPOL assessment reporting period; phishing cases exceed 10,000 in 33% of countries and phishing click rates reach 5.5 per 1,000 individuals monthly.
  • INTERPOL publishes the Asia and South Pacific Cyberthreat Assessment Report 2025/2026 and a summary news release.
  • Coverage details that regional scam-center networks generate close to $40 billion annually, with ~$37 billion in romance-baiting/deepfake-linked losses.
  • The Hacker News and other outlets report INTERPOL's warning on rising phishing, ransomware, and AI-driven scams across Asia-Pacific.

Sources cited for INTERPOL Asia & South Pacific Cyberthreat Assessment

Threats related to INTERPOL Asia & South Pacific Cyberthreat Assessment

Detection coverage for TL-2026-0897

As of 2026-06-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0897 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats