Spyware Attacks on Malaysian Firms Double in H1 2025

From January to June 2025, Kaspersky enterprise tools intercepted more than 96,530 spyware attacks aimed at Malaysian organisations. I find the surge hard to ignore because it represents a 124 percent leap from the 43,056 cases logged in the same period last year. This spike now places Malaysia among the three fastest rising spyware hotspots in Southeast Asia, trailing just behind Singapore.

The timing mirrors Malaysia’s rapid economic transformation. The digital economy is expected to contribute a quarter of national GDP in 2025 and inch toward 30 percent by 2030. I’ve seen how fast companies in finance, logistics, manufacturing and government linked sectors are adopting digital systems, cloud tools and connected infrastructure. Cybercriminals see the same trend and are reshaping their tactics to steal high value data that flows through these environments.

NordVPN

Kaspersky warns that the sheer rise in targeted spyware attempts should prompt every Malaysian business to reassess its defences. Many people still misunderstand spyware, assuming it behaves like destructive malware. Spyware quietly installs itself on a device, collects data and watches user activity without disrupting the system. It sits silently, taking screenshots, recording keystrokes and tracking browsing behaviour, then passes everything to an attacker.

A typical infection follows a simple pattern. It infiltrates through a malicious app, contaminated file or compromised website. It records information through keylogging and screen capture. It then sends the harvested data to its creator, who either uses it directly or sells it on underground markets. Over time, attackers refine the code to observe more precise actions such as banking logins, stored PINs, email addresses, credit card numbers or cloud account credentials.

The rise of commercial spyware worries me even more. These tools are created by private firms and sold legally to governments or enforcement bodies. Their capabilities resemble top tier malware. They can intercept calls, read messages, track movements and wipe traces of their activity. Some variants exploit zero click vulnerabilities, meaning infection can occur without the user tapping anything. Pegasus remains the most well known example, capable of full device surveillance through messaging apps and operating system loopholes. In 2024, Kaspersky’s GReAT team devised a lightweight method to detect advanced iOS spyware through the largely overlooked Shutdown.log file.

“Malaysia’s ambition to become a regional hub for AI, cloud and hyperscale data centres, backed by RM169.2 billion in global investments, has inevitably drawn more spyware actors,” said Simon Tung, General Manager for ASEAN and Asia Emerging Countries at Kaspersky. I share this view because the growing flow of sensitive data attracts groups motivated by profit, espionage or corporate advantage.

He adds that as the nation edges toward a digital economy that powers a quarter of its GDP by 2030, the motivation for attackers will intensify. Spyware campaigns now target new technologies and outdated systems at the same time, showing how quickly threat actors adapt. This is why I consider threat intelligence essential for any business that wants to make informed security decisions.

Total protection against spyware is challenging, but Kaspersky outlines steps that reduce exposure. Keep all software updated, especially operating systems, browsers and messaging apps. Avoid clicking suspicious links because a single visit can trigger an infection. Use a VPN to shield internet traffic and reduce redirection risks. Reboot devices often because some spyware cannot survive restarts. Install trusted security tools across all devices. Finally, rely on up to date threat intelligence to understand the tactics and techniques used by attackers.