While most cyberthreat categories recorded a decline over the past year, cyberespionage has continued to intensify across Africa, the Middle East, and Turkiye (META). New data reveals that spyware attacks in Africa increased by 40%, while password stealer attacks grew by 31%.
The findings were presented by experts from Kaspersky’s Global Research and Analysis Team (GReAT) at the recent Cyber Security Weekend – META event.
According to Kaspersky, the cyberespionage landscape across the region remains largely driven by geopolitical tensions, regional conflicts, and ideological motivations. As intelligence gathering becomes a top priority for both Advanced Persistent Threat (APT) actors and cybercriminals, both organizations and individuals face an increasing barrage of attacks aimed at stealing sensitive data and establishing long-term system access.
Businesses and enterprise environments across Africa experienced a sharp spike in targeted threats over the past year. According to Kaspersky’s detection metrics for African organizations, password stealers rose by 51%, backdoor detections increased by 23%, and spyware detections grew by 16%.
These malware variants are typically deployed to breach corporate networks, exfiltrate confidential data, maintain persistent access, and prepare systems for secondary targeted attacks.
Kaspersky GReAT is currently tracking more than 20 APT groups actively targeting entities in the META region. Researchers highlighted the MuddyWater APT group, which recently targeted Middle Eastern organizations during the Gulf conflict using custom loaders, injectors, previously unknown Remote Access Trojans (RATs), credential stealers, and a modular exfiltration framework to bypass defenses.
The surge in digital espionage extends beyond corporate boundaries to individual consumers. Over the past year, password stealer attacks targeting individuals in Africa rose by 32%. Stolen credentials are routinely used to hijack accounts, launch follow-on attacks, extort victims, or traded on dark web marketplaces.
Simultaneously, mobile cyberespionage has emerged as a high-value vector due to the vast amounts of personal, corporate, and financial data stored on smartphones.
“Smartphones have become one of the most valuable sources of intelligence for cyberespionage actors,” said Dmitry Galov, Head of Global Research and Analysis Team (Russia and CIS) at Kaspersky.
“While Android devices continue to be widely targeted by mobile spyware, we are also observing an increasing number of reports of sophisticated campaigns targeting iOS, as demonstrated by Operation Triangulation and, more recently, Coruna attacks. These findings show that advanced mobile threats continue to evolve across both major platforms, making mobile security an essential part of cyber resilience for both organisations and individuals,” he added.

