Kenyan Organisations Being Attacked By The Basics – Report

0
Allan Juma, Lead Cybersecurity Engineer at ESET.

Allan Juma, Lead Cybersecurity Engineer at ESET.

ESET Research has released its latest Threat Report summarising how the threat environment has changed since December 2025, drawing on ESET telemetry and the analysis of its threat detection and research teams.

Globally, the report describes a period in which artificial intelligence has become both a target for attackers and how they carry out attacks, with ESET analysing around 900,000 AI skills and finding more than 3,000 to be outright malicious. For Kenyan organisations, however, the more useful reading of the data is that the local threats are not exotic. They are the same techniques seen elsewhere, applied locally, and the exposure they exploit owes more to unaddressed fundamentals than to novelty.

“The threats facing Kenya are the same around the world, and email remains one of the most reliable ways of getting ransomware into the organisation,” says Allan Juma, Lead Cyber Security Engineer at ESET. The report found that malicious email attachments continue to do all the work and are dominated by scripts (46.2%), followed by Microsoft Office documents (14.4%), PDFs (11.9%) and archives (9.7%). Kenya conforms to the same distribution, with the methods remaining popular because they are effective. 

QR code phishing, or “quishing”, has reached record levels globally, with around 11% of all detected phishing emails carrying a QR code in the reporting period, often moving the victim onto a personal mobile device that sits outside corporate defences. In Kenya, ESET telemetry recorded a 145% increase in quishing between the second half of 2025 and the first half of 2026, although the comparison spans an incomplete baseline and is best treated as directional rather than precise. In absolute terms, Kenya’s share remains well below that of the largest markets, such as North America at 12.4%, which suggests the technique has room to grow locally rather than that it has passed its peak.

“QR codes have been adopted everywhere and are a convenience that attackers are counting on,” says Tony Anscombe, Chief Security Evangelist at ESET. “Many people still scan a QR code without stopping to consider where it leads.”

The more instructive finding for Kenya involves an old technique with exploitation attempts against CVE-2017-0199, a vulnerability in outdated Microsoft Office installations that allows malicious code to run when a victim opens a specially designed document, more than doubling in Kenya between H2 2025 and H1 2026.

The flaw is among the most frequently detected globally in the report, and it has reportedly been built into off-the-shelf attack frameworks such as GhostX, sold on dark web marketplaces. That a vulnerability first disclosed in 2017 remains a productive route into Kenyan systems points to the central weakness in the local picture, which is not a shortage of sophistication among defenders, but a backlog of basics left unattended. 

That weakness is visible elsewhere in the infrastructure, with remote desktop endpoints left reachable over the open internet, in some cases running long-unsupported versions of Windows, and without the hardening that would keep them out of an attacker’s line of sight. “The key takeaway is to do the basics,” says Juma. “Patch your endpoints, protect them at a minimum standard, and stop using default ports and passwords. Too much of what we are seeing comes down to organisations not doing the fundamentals.” 

In Kenya, ESET telemetry recorded a pronounced rise in an infostealer and dropper tracked as Aotera, which has become the fourth most frequently detected malware family in the country and is used to deliver further payloads, among them AgentTesla, Formbook, PureLogs, PhantomStealer and Vidar. AgentTesla, at 12.1%, and Formbook, at 10.2%, are the two most common infostealer families worldwide in the report, so the local delivery mechanism feeds directly into tooling that is already prevalent across the globe. 

Several Kenyan victims are paying out for what they believe is ransomware when no genuine ransomware is present. “Organisations need to understand what ransomware is and how to verify a genuine attack before they respond to one,” says Juma. The lesson is the one that runs through the rest of the local picture, namely that the answer lies less in new tools than in the discipline to check, patch and harden what is already in place. Read together, the findings describe a threat environment in which the greatest risk to Kenyan organisations comes less from what is new than from what is known and left unaddressed.” 

Leave a Reply

Your email address will not be published. Required fields are marked *