AI and APT Cyber Threats in Southeast Asia: Security Challenges and Solutions for 2025
The cybersecurity landscape for companies in Southeast Asia has undergone a dramatic transformation in recent years. The adoption of hybrid workforces, multicloud architectures, and complex third-party supply chains has expanded the attack surface beyond traditional protection. Meanwhile, threat actors are now more mature, organised, and persistent, supported by artificial intelligence (AI).
Recent data from Kaspersky shows an alarming scale of threats in the region throughout 2025. Indonesia has become one of the main targets with a significant volume of attacks.
Kaspersky summarised three main challenges defining the current cybersecurity imbalance in Southeast Asian organisations:
Modern attackers move faster in data exfiltration, narrowing the detection window for security teams. Advanced Persistent Threats (APTs) remain the highest risk. One clear example is the ‘Mysterious Elephant’ campaign targeting government entities in the Asia Pacific with highly disciplined techniques, from credential theft to hidden persistence.
Security teams are urged to shift from reactive handling to intelligence-based defence, focusing on real-time endpoint visibility and response automation to reduce dwell time.
AI has become a double-edged sword. Attackers use AI to automate reconnaissance and create highly convincing phishing. On the other hand, companies face a global talent crisis. As many as 41% of security professionals report that their organisations are understaffed.
The strategic solution is not simply to add personnel, but to embed AI-assisted automation into workflows to handle alert triage and investigation, enabling small teams to operate with great effectiveness.
Many companies are trapped in fragmented architectures with dozens of standalone tools that do not communicate with each other. Simon Tung, General Manager for ASEAN at Kaspersky, highlighted that security teams spend too much time on manual integration, triggering alert fatigue.
To address this challenge, organisations must consolidate platforms through integrated solutions such as EDR and XDR. This step aims to centralise telemetry, close visibility gaps, and lower the total cost of ownership (TCO).
Through product lines such as Kaspersky Next Expert, companies can adopt AI-based continuous protection capable of real-time cross-domain correlation, ensuring defences remain robust even amidst limited human resources.