Kaspersky reports sharp rise in AI-themed malware attacks on SEA SMBs

July 30, 2026 - 12:00
From January to April 2026, Kaspersky security solutions detected more than 33,300 attacks targeting small and medium-sized businesses (SMBs) globally in which malware or unwanted software for PCs was disguised as popular artificial intelligence (AI) services. The figure rose nearly fivefold compared with the same period in 2025.

In Southeast Asia (SEA), more than 1,800 such attacks were detected, marking an almost sevenfold increase from the same period last year.

Ahead of International SMB Day on June 27, a new Kaspersky report provides an analysis of emerging threats and mitigation strategies to help SMBs protect themselves against an evolving threat landscape.

Kaspersky experts examined how threat actors target SMBs with malware disguised as legitimate AI services, reflecting the growing use of such tools in business operations. During the first four months of 2026 in SEA, the most common lures were malware posing as ChatGPT (44%), DeepSeek (33%), and Claude (11%).

Global SMB attacks involving malware disguised as five popular AI applications, January-April 2025 and 2026

Among the malicious files detected in the SMB sector and disguised as AI services, Kaspersky experts identified various types of Trojware, including malware capable of downloading and running additional malicious software on compromised devices.

Trojware disguises itself as harmless files to trick users into installing it. Depending on the malware type, it can steal, delete, block, modify or copy users' data, as well as carry out other malicious activities. As a result, Trojware poses a significant cybersecurity threat to entrepreneurs and businesses.


However, in 2026, Kaspersky telemetry detected even more attacks targeting SMBs in which malware or unwanted software for PCs was disguised as messaging and video conferencing applications, including Telegram, WhatsApp, Zoom and Microsoft Teams.

From January to April, Kaspersky solutions blocked nearly 415,000 such attacks. The number changed only marginally compared with the previous year, indicating that fake communication apps remain a persistent cyberthreat.

"The threat landscape is evolving, with new lures constantly emerging. During the first four months of this year, our solutions for small and medium-sized businesses detected hundreds of attacks in which malware or unwanted software was disguised as OpenClaw — an AI tool that has rapidly gained popularity in 2026. Corporate employees are increasingly using AI services and other publicly available tools in their daily work.

To stay safe, SMB employees, as well as all users, should exercise caution when downloading software from the internet. Always verify website addresses and links in suspicious emails, and use robust security solutions," said Vasily Kolesnikov, security expert at Kaspersky.


"As adversaries continually refine their methods to exploit human error, the need for up-to-date cybersecurity awareness training for businesses of all sizes has never been greater. However, many microbusinesses struggle to dedicate the time and budget needed to keep staff informed about the latest threats and attack techniques.

We believe this challenge can be addressed through security solutions designed for small businesses that combine robust protection with accessible cybersecurity education," added Rodion Pyanov, Product Manager for Kaspersky Small Office Security.

"Cybercriminals often view SMBs as low-hanging fruit, exploiting security weaknesses that can result from limited resources. With more than 90 per cent of businesses in Southeast Asia classified as SMBs, the region will remain a prime target for threat actors, highlighting the urgent need for companies to strengthen their cybersecurity posture.

As the backbone of the Southeast Asian economy, SMBs cannot afford to overlook investment in cybersecurity. The key is finding solutions that match their operational needs and financial capabilities," said Adrian Hia, Managing Director for Asia Pacific at Kaspersky.

The full report on the SMB threat landscape is available here.

To protect businesses from cyberthreats, Kaspersky recommends:

• Choosing security solutions that match the organisation's budget, size and industry requirements, while offering scalability and easy integration. Companies should also establish clear policies governing the use of external services and resources.

• Defining access controls for corporate resources, including email accounts, shared folders and online documents.

• Regularly backing up critical data to ensure business information can be restored in the event of an emergency./.

E-paper