Home News ESET Threat Report: Kenyan Organisations Under Fire from Basic, Well-Known Attack Methods

ESET Threat Report: Kenyan Organisations Under Fire from Basic, Well-Known Attack Methods

by Jacky Muraba
69 views

ESET Research has published its latest Threat Report, outlining how the threat landscape has evolved since December 2025, based on ESET telemetry and analysis from its detection and research teams. Globally, the report highlights a period in which artificial intelligence has become both a target for attackers and a means of carrying out attacks — ESET examined roughly 900,000 AI skills and found more than 3,000 to be outright malicious. For organisations in Kenya, though, the more relevant takeaway is that local threats aren’t novel. They’re familiar techniques being applied locally, and the vulnerabilities they exploit stem more from neglected fundamentals than from anything new.

The H1 2026 Threat Report’s global findings — with artificial intelligence now both a target and a tool, and established techniques being adapted to new platforms — largely mirror rather than diverge from the picture in Kenya.

QR code phishing has hit record levels worldwide, with ESET telemetry showing a 145% rise in Kenya between H2 2025 and H1 2026, though an incomplete baseline means the figure should be treated with some caution.

  • Attempts to exploit an old Microsoft Office vulnerability, CVE-2017-0199, more than doubled in Kenya over the same period, highlighting how unpatched fundamentals remain a viable entry point.
  • An infostealer and dropper known as Aotera has climbed to become the fourth most detected malware family in the country.

“The threats facing Kenya are the same around the world, and email remains one of the most reliable ways of getting ransomware into the organisation,” says Allan Juma, Lead Cyber Security Engineer at ESET. The report found that malicious email attachments continue to do all the work and are dominated by scripts (46.2%), followed by Microsoft Office documents (14.4%), PDFs (11.9%) and archives (9.7%). Kenya conforms to the same distribution, with the methods remaining popular because they are effective.

QR code phishing, or “quishing,” has surged to record levels globally, with roughly 11% of detected phishing emails containing a QR code during the reporting period — often directing victims to a personal mobile device outside the reach of corporate security. In Kenya, ESET telemetry recorded a 145% jump in quishing between the second half of 2025 and the first half of 2026, though the comparison covers an incomplete baseline and should be read as directional rather than exact. In absolute terms, Kenya’s share still trails well behind larger markets like North America, at 12.4%, suggesting the technique still has room to expand locally rather than having already peaked.

“QR codes have been adopted everywhere and are a convenience that attackers are counting on,” says Tony Anscombe, Chief Security Evangelist at ESET. “Many people still scan a QR code without stopping to consider where it leads.”

A more telling finding for Kenya concerns an older exploit: attempts to abuse CVE-2017-0199, a vulnerability in outdated Microsoft Office installations that lets malicious code execute when a victim opens a specially crafted document, more than doubled in the country between H2 2025 and H1 2026. The flaw ranks among the most commonly detected worldwide in the report and has reportedly been incorporated into ready-made attack kits such as GhostX, sold on dark web marketplaces. The fact that a vulnerability first disclosed in 2017 still serves as an effective entry point into Kenyan systems underscores the core issue locally — not a lack of sophistication among defenders, but a backlog of unaddressed basics.

That same weakness shows up elsewhere in the infrastructure, with remote desktop endpoints exposed to the open internet — some still running long-unsupported versions of Windows — and lacking the hardening needed to stay off attackers’ radar. “The key takeaway is to do the basics,” says Juma. “Patch your endpoints, protect them at a minimum standard, and stop using default ports and passwords. Too much of what we are seeing comes down to organisations not doing the fundamentals.”

In Kenya, ESET telemetry recorded a marked increase in an infostealer and dropper known as Aotera, now the fourth most frequently detected malware family in the country, used to deliver additional payloads including AgentTesla, Formbook, PureLogs, PhantomStealer, and Vidar. AgentTesla (12.1%) and Formbook (10.2%) rank as the two most widespread infostealer families globally in the report, meaning the local delivery method feeds directly into tools already common worldwide.

A number of Kenyan victims have paid out believing they were dealing with genuine ransomware when none was actually present. “Organisations need to understand what ransomware is and how to verify a genuine attack before they respond to one,” says Juma. This reflects a broader theme running through the report’s Kenyan findings — that the solution lies less in acquiring new tools and more in the discipline to check, patch, and harden existing systems. Taken together, the findings suggest that the biggest risk facing Kenyan organisations comes not from what’s new, but from what’s already known and left unaddressed.

You may also like

Leave a Comment