advertisement
Kenyan Organisations Face Familiar Cyber Threats
Kenyan organisations are facing a cyber threat environment that looks increasingly similar to what is being seen globally, but the biggest risks are often coming from vulnerabilities and security practices that have been known for years.
The latest ESET Threat Report, which analyses threat activity since December 2025 using ESET telemetry and research, suggests that attackers are continuing to rely on familiar techniques such as malicious email attachments, phishing, outdated software and exposed remote desktop services. At the same time, artificial intelligence is becoming increasingly intertwined with the threat landscape, both as a target for attackers and as a tool for developing and carrying out attacks.
ESET said it analysed around 900,000 AI skills globally, identifying more than 3,000 that were outright malicious. However, for Kenyan organisations, the more immediate concern may not be emerging AI-driven attacks but the continued effectiveness of conventional techniques.
advertisement
“The threats facing Kenya are the same around the world, and email remains one of the most reliable ways of getting ransomware into the organisation,” says Allan Juma, Lead Cyber Security Engineer at ESET.
Email remains a major entry point
Malicious email attachments continue to provide attackers with a relatively straightforward way into organisations. According to ESET, scripts accounted for 46.2% of malicious email attachments detected during the reporting period. Microsoft Office documents followed at 14.4%, PDFs at 11.9% and archives at 9.7%.
Kenya broadly follows the same pattern, indicating that attackers do not necessarily need highly sophisticated techniques to compromise organisations. Instead, commonly used file formats and social engineering remain effective because employees continue to interact with them as part of their normal work.
advertisement
Another established technique is also becoming more prominent. QR code phishing, commonly known as “quishing”, reached record levels globally during the reporting period. About 11% of detected phishing emails contained a QR code, often directing victims to websites through their personal smartphones. The approach can be particularly useful to attackers because the victim may move from a corporate computer, where security controls are in place, to a personal mobile device that is subject to different protections.
In Kenya, ESET telemetry recorded a 145% increase in quishing between the second half of 2025 and the first half of 2026. ESET cautions that the comparison is based on an incomplete baseline and should therefore be viewed as directional rather than a precise measure of growth.
Kenya’s overall share of quishing activity remains below that of some major markets. North America, for example, accounted for 12.4% of detections, suggesting that the technique may still have considerable room to expand in Kenya.
advertisement
“QR codes have been adopted everywhere and are a convenience that attackers are counting on,” says Tony Anscombe, Chief Security Evangelist at ESET. “Many people still scan a QR code without stopping to consider where it leads.”
A nine-year-old vulnerability remains a problem
Perhaps more significant for Kenyan organisations is the continued exploitation of vulnerabilities that should have been addressed years ago. ESET recorded more than a doubling of exploitation attempts against CVE-2017-0199 in Kenya between the second half of 2025 and the first half of 2026. The vulnerability affects outdated Microsoft Office installations and can allow malicious code to execute when a victim opens a specially crafted document.
First disclosed in 2017, CVE-2017-0199 remains among the most frequently detected vulnerabilities globally in ESET’s latest report. It has also reportedly been incorporated into commercially available attack frameworks, including GhostX, which has been sold through dark web marketplaces. Its continued effectiveness in Kenya highlights a problem that extends beyond the vulnerability itself. For organisations running outdated software, an old vulnerability can remain a viable attack route long after security researchers and vendors have identified the weakness and issued fixes.
The issue is also reflected in the exposure of remote desktop services. ESET found instances of remote desktop endpoints accessible from the public internet, including systems running versions of Windows that are no longer supported. Such systems can provide attackers with a direct path into an organisation when they have not been properly patched, secured or restricted.
“The key takeaway is to do the basics,” says Juma. “Patch your endpoints, protect them at a minimum standard, and stop using default ports and passwords. Too much of what we are seeing comes down to organisations not doing the fundamentals.”
Infostealers continue to feed the wider threat ecosystem
The Kenyan threat landscape is also seeing increased activity from malware designed to steal information and deliver additional malicious payloads. ESET telemetry recorded a pronounced increase in Aotera, an infostealer and dropper that has become the fourth most frequently detected malware family in Kenya. Aotera can be used to deliver other malware, including AgentTesla, Formbook, PureLogs, PhantomStealer and Vidar. The connection is significant because the payloads being delivered in Kenya are not isolated threats. They include malware families that are already widely used internationally.
Globally, AgentTesla accounted for 12.1% of infostealer detections in the report, while Formbook represented 10.2%, making them the two most commonly detected infostealer families worldwide during the reporting period.
This demonstrates how local attacks can be connected to a much broader cybercrime ecosystem, with attackers using established malware families and delivery mechanisms rather than developing entirely new tools for each market.
When ransomware isn’t actually ransomware
Another concern emerging from the Kenyan data involves incidents in which organisations believe they are dealing with ransomware even when no genuine ransomware infection is present. This can create a second problem for victims because responding to an assumed ransomware attack without first establishing what has actually happened can lead to inappropriate decisions, unnecessary costs and further disruption.
“Organisations need to understand what ransomware is and how to verify a genuine attack before they respond to one,” says Juma.
The finding reinforces a broader theme running through ESET’s assessment of the Kenyan market. While artificial intelligence is changing how cybercriminals operate and new attack techniques continue to emerge, organisations do not necessarily need to be targeted by a highly sophisticated or novel attack to suffer a serious breach.
Outdated software, exposed remote access systems, weak credentials, malicious attachments and phishing remain effective because they exploit gaps in basic security practices. For Kenyan organisations, therefore, the challenge may be less about anticipating the next entirely new form of cyberattack and more about closing the weaknesses that attackers already know how to exploit.
The latest ESET findings suggest that strengthening patch management, securing remote access, enforcing stronger authentication, improving employee awareness and verifying suspected incidents could go a long way towards reducing exposure.
As cybercriminals increasingly add AI to their toolkit, the fundamentals of cybersecurity remain relevant. In Kenya, some of the most persistent threats continue to come from vulnerabilities and practices that organisations have already had years to address.