Skip to main content

Kaspersky identifies cyberespionage as a growing threat across the Middle East, Turkiye and Africa

3 August 2026

At the recent Cyber Security Weekend – META event, Kaspersky's Global Research and Analysis Team (GReAT) experts presented the latest findings on the cyberespionage threat landscape across the Middle East, Turkiye, and Africa (META) region. While most cyberthreat categories declined over the past year, cyberespionage continued to intensify in the region. Thus, throughout the past year, spyware attacks increased by 40% in Africa, while password stealer attacks grew by 31% in Africa.

The cyberespionage landscape across the META region continues to be driven by geopolitical tensions, regional conflicts and ideological motivations. As intelligence gathering becomes increasingly important for both Advanced Persistent Threat (APT) actors and cybercriminals, organisations and individuals alike are facing a growing number of attacks designed to steal sensitive information and establish long-term access to compromised systems.

If we specifically look at cyberthreats aimed at businesses, organisations in Africa experienced a sharp increase in espionage-related threats over the past year. Spyware detections rose by 16% in Africa, password stealer attacks by 51%, and backdoor detections by 23%. These types of malware are commonly used to infiltrate corporate environments, steal confidential information, establish persistent access, and facilitate subsequent stages of targeted attacks.

As geopolitics remains a key driver for APT attacks, such actors remain among the most significant cyber risks in the region for businesses and governmental entities. To maximise persistence and evade detection, they continuously refine their toolsets, deploying increasingly sophisticated malware capable of maintaining long-term access to compromised systems while collecting valuable intelligence. In 2026, Kaspersky GReAT is tracking more than 20 APT groups actively targeting organisations across the META region.

Recent research by Kaspersky GReAT found the MuddyWater APT group targeting organisations across the Middle East during the Gulf conflict using previously unseen malware chains. The campaign employed custom loaders, injectors, previously unknown remote access trojans (RATs), credential stealers, and a modular data exfiltration framework, highlighting the group's rapid development of new tools to steal sensitive information and evade detection.

The increase in espionage activity is not limited to organisations. Individuals are also increasingly targeted. Over the past year, attacks involving password stealers increased by 32% in Africa. The stolen information can subsequently be used to hijack accounts, conduct follow-on attacks, extort victims, or sold to third parties on underground marketplaces.

Another rapidly growing trend is mobile cyberespionage. As smartphones increasingly store personal communications, corporate information, authentication credentials, and financial data, they have become high-value targets for attackers. 

“Smartphones have become one of the most valuable sources of intelligence for cyberespionage actors. While Android devices continue to be widely targeted by mobile spyware, we are also observing an increasing number of reports of sophisticated campaigns targeting iOS, as demonstrated by Operation Triangulation and, more recently, Coruna attacks. These findings show that advanced mobile threats continue to evolve across both major platforms, making mobile security an essential part of cyber resilience for both organisations and individuals,” said Dmitry Galov, Head of Global Research and Analysis Team, Russia and CIS, at Kaspersky.

As cyberespionage threats continue to evolve, Kaspersky recommends that organisations adopt a layered cybersecurity approach, combining continuous vulnerability management, timely patching, employee awareness training, threat intelligence, and advanced security solutions such as Kaspersky Next, which help detect sophisticated targeted attacks and protect organisations from long-term compromise.

Kaspersky identifies cyberespionage as a growing threat across the Middle East, Turkiye and Africa

At the recent Cyber Security Weekend – META event, Kaspersky's Global Research and Analysis Team (GReAT) experts presented the latest findings on the cyberespionage threat landscape across the Middle East, Turkiye, and Africa (META) region. While most cyberthreat categories declined over the past year, cyberespionage continued to intensify in the region. Thus, throughout the past year, spyware attacks increased by 40% in Africa, while password stealer attacks grew by 31% in Africa.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases