Revealing new telemetry data at the Cyber Security Weekend, Kaspersky highlights how generative AI, malware evolution, and cloud-based exfiltration are reshaping the security landscape across the Middle East, Turkiye, and Africa.
The Global Research & Analysis Team (GReAT) at Kaspersky has released its latest threat landscape insights for the first half of 2026, uncovering a sharp rise in sophisticated, AI-accelerated cyberattacks across the Middle East, Turkiye, and Africa (META) region.
Driven by geopolitical instability and the rapid weaponization of artificial intelligence, cybercriminals are streamlining operations, scaling attacks, and exploiting vulnerabilities in websites, emails, and web services at an unprecedented rate.
Kaspersky’s detection systems intercepted millions of online threats across the META region during H1 2026, reflecting the heavy volume of web-borne attacks targeting regional infrastructure:
- South Africa: 5.7 million online attacks stopped.
- Kenya: 4.5 million online attacks stopped.
- Nigeria: 1.6 million online attacks stopped.
In terms of user exposure, Turkiye recorded the highest percentage of affected users at 22.8%, followed closely by Kenya (21.2%), Qatar (19.3%), Nigeria (18.4%), and South Africa (17.2%). Conversely, Saudi Arabia, Jordan, and Pakistan registered the lowest proportion of targeted users.
According to Kaspersky experts, threat actors are aggressively integrating large language models (LLMs) into every stage of the cyberattack lifecycle, from generating convincing phishing templates to writing core functional components of malware.
Recent campaigns illustrate this shift:
- FunkSec Group: Deployed Rust-based malware capable of data theft, encryption, and process manipulation using AI-assisted development.
- RevengeHotels Campaign: Leveraged LLMs to generate portions of infector and downloader code.
“We expect AI to remain one of the key factors shaping the threat landscape in 2026, as we already see how it is reshaping attacker workflows and accelerating their operations,” noted Sergey Lozhkin, Head of GReAT in APAC and META at Kaspersky. “By lowering the time and cost required to develop and adapt malicious tools, AI allows threat actors to iterate faster and scale their efforts. Defenders should be prepared for quicker shifts in tactics.”
Beyond generative code, Kaspersky identified several critical threat vectors that organizations must watch closely:
- AI-Driven Malware Evolution: Generative models rewrite code across different architectures to evade traditional signature detection.
- Cloud-Based Data Exfiltration: Attackers route stolen information through legitimate cloud and file-sharing platforms to mask traffic as normal user behavior.
- Operations-Targeting Ransomware: Modern ransomware gangs disrupt business processes and physical production lines—not just encrypt data—to force extortion payments.
- AI Agents as Persistence Mechanisms: Compromised enterprise AI agents with broad system access are being manipulated via system prompts or configuration changes to continuously pull malicious payloads.
- Malicious AI Skills: Attackers exploit trusted AI skills to steal sensitive data, manipulate behavior, and establish backdoors inside enterprise networks.
To counter these advanced threats, Kaspersky advises organizations to prioritize continuous vulnerability patching, advanced employee training, threat intelligence integration, and robust detection platforms like Kaspersky Next.






























