Friday 25 Sep 2026
main news image

This article first appeared in Digital Edge, The Edge Malaysia Weekly on September 8, 2025 - September 14, 2025

A good cybersecurity framework is no different from maintaining a good train system, and strong preventative measures will continue to be the best defence against cyberthreats. However, with the rise of dark artificial intelligence (Dark AI), staying updated on the latest information on cybersecurity will be crucial in ensuring that individuals and organisations can stay ahead of the threat landscape.

Having a good detection rate is important as the first line of defence. The more you can detect, the more you can protect your systems, said Adrian Hia, managing director of Kaspersky Asia-Pacific (APAC), at the Kaspersky Cybersecurity Week held at Hoi An, Vietnam, on Aug 5.

“We predict in the next few years, Dark AI will be the next invisible force … I define Dark AI just like the dark web, which is the shadow of the World Wide Web that we use every day today. Dark AI is also a non-regulated, illegal, large language model (LLM) that a lot of threat actors and cybercriminals are using to create their own AI capabilities to [carry out threats],” said Hia.

Threats have also escalated as the scale has risen exponentially. Compared with 1994, where one new virus emerged every hour, 2006 had a new virus appearing every minute. Within half a decade, 2011 saw a new virus every second.

“We predict in the next few years, Dark AI will be the next invisible force … I define Dark AI just like the dark web, which is the shadow of the World Wide Web that we use every day today.” - Hia, Kaspersky Asia-Pacific

“Now, Kaspersky is processing 467,000 samples, over half a million of new malware, new viruses and new ransomware on a daily basis. The question that is asked is why [is this the case, and to answer,] that’s the power of AI,” Hia said.

In his opening remarks, he predicted that in the next few years, the world will see Dark AI models becoming legitimate AI tools where people can use them as a cover and harness their power to create sophisticated ransomware and malware.

Compounded with the rise in connected information technology (IT) and operational technology (OT), the links that are created between each device have introduced new vulnerable points that can be taken advantage of by cybercriminals.

“Be it a smart car, a smart laptop or a smart home, as long as you have anything connected to the internet, it requires you to install protection today,” he said.

Hia recommended that companies look into securing prevention measures first before fortifying incidence responses. The mindset that should be adopted is that one must assume that a breach is inevitable.

Basic cyber hygiene tips, such as staying away from random links or installing multifactor authentication, will still be important in being digitally safe. However, with the advancements in technology, it will be even more difficult to stay safe with rapid threat sophistications.

Noushin Shabab, lead security researcher for Kaspersky’s global research and analysis team, suggests that people can take an extra step in protecting themselves through the installation of advanced security solutions.

Some threat actors will use sophisticated tools that target unpatched vulnerabilities, so even if there is no link to click, users can still be susceptible to scams or threats through unseen digital cracks. Advanced security solutions ensure that an individual can be protected from additional fronts that cannot be easily detected.

“Advanced security solutions can detect an attack, even if it is completely new just based on the anomalies, the suspicious behaviour and the different things that haven’t happened in this environment before but are appearing now. So having an advanced security solution in place is an important thing that cannot be replaced with educating users,” says Noushin.

“For the past decade, we have observed that year after year, threat actors seem to be collaborating or sharing tools, even sharing infrastructure.” - Noushin, Kaspersky

Identifying threat actors

Noushin shares that identifying threat actors and advanced persistent threat (APT) groups today have become more difficult compared with what it was like a few years ago.

Previously, APT groups were able to be differentiated based on their own tools, infrastructure and operating methods, but this strategy has evolved, and actors have started to branch out from working independently.

“For the past decade, maybe, we have observed that year after year, threat actors seem to be collaborating or sharing tools, even sharing infrastructure. Working together prevents them from developing similar capabilities on their own, but it also makes the distinction and attribution for us a lot more difficult, and it sometimes makes the analysis and investigation process a little slower,” Noushin says.

Mysterious Elephant, an APT group targeting Pakistan’s foreign affairs sector, was identified in 2023 as a new actor using an updated version of a tool previously linked to several other threat groups in a specific attack. This suggests that Mysterious Elephant may be leveraging tools discarded or shared by other actors in the region to launch fresh malicious campaigns.

However, beyond such indicators, it remains difficult to determine the nature or extent of relationships between different threat groups.

“The communication and collaboration internally between threat actors are, most of the time, unknown to us because we don’t track attacks from the source. We track attacks when they happen or are in an attempt to compromise systems of victims,” says Noushin.

She adds that activity between threat actors every now and then tends to be heard of through communication leaks between members of ransomware groups or cybercriminal groups. Authorities such as Interpol, Europol, the FBI or local police agencies can also collect information through arrests and confiscation of their systems.

With AI in the picture, especially with the emergence of Dark AI, cybercriminals are able to create more frequent, advanced and targeted attacks with increasing efficacy.

“Cybercriminals can use Dark AIs to produce malicious tools and codes. They have been trained on a ton of codes from malicious software, and from proof of concepts that researchers have been developing to exploit vulnerabilities for good reason. But there are still codes that can be adopted to do harmful activities,” she says.

Espionage drives most cybercrime in APAC

More than 90% of cybercrime in Asia-Pacific are cyber espionage activities, Noushin shares, with a majority of these malicious activities targeting individuals instead of organisations.

An example of the wedding invitation scam from the Tria Stealer campaign

“It’s quite important to learn about these cybercrime activities because they usually target individuals, not big organisations. As people living in this region, these threats can affect any of us,” she says.

APAC is an interesting target area for cybercriminals due to the close proximity between each country and the similarities in culture and languages. Through collaboration from threat actors, cybercriminals are able to cover more ground by sharing information between parties.

“In a lot of cases in APAC, the threat actor is targeting more than one country, so they target countries that are aligned politically with each other, or countries that both have something potentially interesting for a specific attacker,” explains Noushin.

A scam campaign known as Tria Stealer has been circulating in Malaysia and Brunei, disguising itself as fake wedding invitations that request money. The malware spreads via WhatsApp and Telegram by forwarding messages to mimic authentic invitations.

When victims open the attached file, the malware installs itself on their phones and propagates through their contact lists, widening its reach.

While using wedding invitations as a scam tactic may seem unusual elsewhere, researchers note it was effective in Malaysia and Brunei because it tapped into local demographics and cultural practices.

Another threat actor active in Malaysia is ToddyCat, first identified in 2020. In 2024, researchers observed new activity from the group, which has incorporated tools designed to harvest information from victims and exfiltrate it to various cloud environments.

The group’s latest tactics involve exploiting vulnerable Windows kernel drivers to disable monitoring systems, making it harder for analysts to detect and respond to intrusions.

During this window of confusion, ToddyCat deploys multiple modules to disrupt operations and locate valuable information within the network. Once this stage is complete, the main payload is executed to steal and exfiltrate data.

“The main payload is usually the most important tool for the attackers. They don’t drop the main tool of their arsenal right away. When they compromise a system, the attackers will usually try to protect the main tool by adding different layers of infection through the installation of different, smaller and less sophisticated tools, to collect information about the target environment,” Noushin explains.

She also mentioned SparkCat, a crypto-stealing trojan that managed to enter both Apple’s App Store and Google Play Store. It is known to be the first instance of optical recognition-based malware. It works by scanning the galleries of different users to look for recovery words associated with crypto wallets and steal the relevant information to relay it back to the hacker server.

SparkCat’s primary target market points towards the United Arab Emirates, Asia and Europe. Different versions of this tool were released over the span of a few months but have since been taken down by both Apple and Google.

Tetris Phantom is another organisation targeting a specific government in Southeast Asia. The group is a relatively new discovery, but it has been persistent for over seven years in developing sophisticated tools to attack secure USB drives and collect sensitive data.

Save by subscribing to us for your print and/or digital copy.

P/S: The Edge is also available on Apple's App Store and Android's Google Play.

      Print
      Text Size
      Share