Kaspersky flags AI-assisted attacks as top threat in Egypt and META
Kaspersky's Global Research and Analysis Team (GReAT) has published its threat landscape findings for the first half of 2026, presented at the company's Cyber Security Weekend for the Middle East. The report identifies Egypt as having faced 8.3 million blocked web-based attacks between January and June, and positions the growing integration of artificial intelligence into attacker workflows as the defining shift of the period.
The telemetry covers the broader META region. Across those markets, Turkey recorded the highest proportion of users exposed to web-borne threats at 22.8%, followed by Kenya at 21.2% and Qatar at 19.3%. Saudi Arabia, Jordan and Pakistan registered comparatively lower exposure rates, though Kaspersky did not publish absolute figures for those countries.
AI enters the attacker toolkit
The report's central theme is the use of large language models to accelerate and scale malicious operations. Kaspersky researchers say generative models are already being applied to write phishing content, generate initial malware scaffolding, and produce functional code modules. The firm cited two documented campaigns: the FunkSec group, whose Rust-based malware was assessed to have incorporated AI-generated components and is capable of data theft, encryption and process manipulation; and the RevengeHotels campaign from 2025, in which threat actors used language models to generate portions of the infector and downloader code.
Sergey Lozhkin, head of GReAT for APAC and META at Kaspersky, said: "By lowering the time and cost required to develop and adapt malicious tools, AI allows threat actors to iterate faster and scale their efforts. Defenders should be prepared for quicker shifts in tactics."
Beyond AI-assisted development, the report identifies four additional trends the company says organisations should monitor. Cloud-based data exfiltration through legitimate file-sharing services is being used to disguise outbound traffic. Some ransomware groups are now disrupting production processes rather than simply encrypting files, to maximise payment pressure. AI agents with broad system access are flagged as a persistence risk: a compromised agent could be configured to download malicious payloads on each startup. Finally, malicious skills injected into enterprise AI agent frameworks are described as a new attack surface, enabling attackers to manipulate agent behaviour and harvest sensitive data.
Market and regulatory context
Kaspersky's findings arrive in a threat environment where enterprise buyers in the META region are navigating a complex regulatory patchwork. The UAE's National Cybersecurity Strategy and Saudi Arabia's updated NCA regulations both impose incident-reporting obligations and minimum security controls on critical infrastructure operators, creating compliance pressure that elevates the commercial relevance of threat intelligence products.
More broadly, the European Union's NIS2 Directive and the Digital Operational Resilience Act (DORA) in financial services set a precedent that regional regulators are watching closely. As AI-assisted attack tooling becomes commoditised, frameworks that mandate continuous vulnerability management and supply-chain security assessments are likely to tighten across Gulf Cooperation Council markets.
The cybersecurity vendor market itself is consolidating, with platform plays from CrowdStrike, Microsoft Defender and Palo Alto Networks competing for enterprise wallet share alongside specialist threat-intelligence providers. Kaspersky has faced restrictions on sales in the United States and some European markets due to regulatory concerns over its Russian origins, which has shifted its growth focus toward META, APAC and Latin America. That context matters for enterprise procurement teams evaluating the vendor's intelligence output alongside the vendor's own commercial position in regulated markets.
Kaspersky recommends organisations respond with continuous vulnerability management, prompt patching cycles, employee training and deployment of detection tools capable of identifying AI-assisted attack patterns.