Kaspersky warns of surging cyberespionage across META region
Kaspersky's Global Research and Analysis Team (GReAT) has published new threat intelligence showing cyberespionage activity intensifying across the Middle East, Turkiye and Africa (META), even as most other cyberthreat categories declined over the same period. The findings were presented at the firm's Cyber Security Weekend META event on 3 August 2026.
At the consumer and individual level, password stealer attacks increased by 12% across the META region in the past year, while mobile spyware targeting surged 65%, underlining a marked shift in attacker focus toward smartphones. For businesses specifically, the figures are sharper: spyware detections at organisations in the Middle East rose by 20%, password stealer attacks by 30%, and backdoor detections by 10%.
The threat picture
Kaspersky GReAT is currently tracking more than 20 Advanced Persistent Threat (APT) groups actively operating against targets across META. The report names MuddyWater as a notable actor, citing a campaign that targeted Middle East organisations during the Gulf conflict using a previously unseen malware chain. That campaign combined custom loaders, injectors, undisclosed remote access trojans, credential stealers, and a modular data exfiltration framework, suggesting rapid, iterative tool development designed to evade modern endpoint detection.
The research attributes the broader escalation to geopolitical tensions, regional conflicts and ideological motivations rather than financially driven cybercrime, which is a distinction with practical consequences for defenders. APT-grade actors tend to prioritise long-term persistence and intelligence collection over rapid monetisation, making them harder to detect and dislodge once inside a corporate network.
Dmitry Galov, Head of GReAT for Russia and CIS at Kaspersky, noted: "Smartphones have become one of the most valuable sources of intelligence for cyberespionage actors. While Android devices continue to be widely targeted by mobile spyware, we are also observing an increasing number of reports of sophisticated campaigns targeting iOS, as demonstrated by Operation Triangulation and, more recently, Coruna attacks."
Market and regulatory context
Kaspersky's findings sit within a broader pattern of threat-intelligence reports from vendors including CrowdStrike, Mandiant and Microsoft, all of which have documented heightened APT activity linked to Middle Eastern geopolitics in recent years. The META region presents a distinct compliance landscape: organisations operating across Gulf Cooperation Council member states, South Africa and Turkiye face a patchwork of national data protection laws, critical infrastructure regulations and sector-specific cybersecurity mandates that are still maturing relative to frameworks such as the EU's NIS2 Directive or the US NIST Cybersecurity Framework.
Mobile threat escalation is particularly significant given the pace of smartphone adoption across Africa, where mobile-first digital infrastructure means corporate data increasingly resides on personal devices with limited enterprise management controls. The 65% surge in mobile spyware targeting aligns with independent observations from civil-society research groups that have documented commercial spyware deployment against journalists, activists and government officials in the region.
Kaspersky did not disclose the absolute volume of detections behind the percentage figures, which limits direct comparison with third-party benchmarks. The company recommends a layered defensive posture combining vulnerability management, timely patching, employee training and threat intelligence services. Kaspersky's own commercial positioning as a vendor of endpoint and threat-intelligence products means the recommendations carry an inherent promotional dimension, though the underlying statistical trends are consistent with the direction reported by industry peers.
The company has faced regulatory headwinds in Western markets, with US and UK authorities restricting or discouraging use of Kaspersky software on government systems; its research output from GReAT continues to be cited by the broader security community regardless of those commercial constraints.