At Cyber Security Weekend – META, Kaspersky's Global Research and Analysis Team (GReAT) experts presented the latest findings on the cyberespionage threat landscape across the Middle East, Turkiye, and Africa (META). While most cyberthreat categories declined over the past year, cyberespionage continued to intensify in the region. Thus, throughout the past year, spyware attacks increased by 11% in the Middle East, while password stealer attacks grew by 12%, and the number of users targeted by mobile spyware surged by 65%, highlighting attackers' growing focus on smartphones as an attack vector.
The cyberespionage landscape across the META region continues to be driven by geopolitical tensions, regional conflicts and ideological motivations. As intelligence gathering becomes increasingly important for both Advanced Persistent Threat (APT) actors and cybercriminals, organizations and individuals alike are facing a growing number of attacks designed to steal sensitive information and establish long-term access to compromised systems.
If we specifically look at cyberthreats aimed at businesses, organizations in the Middle East experienced the sharpest increase in espionage-related threats over the past year. Spyware detections rose by 20%, password stealer attacks by 30%, and backdoor detections by 10%. These types of malware are commonly used to infiltrate corporate environments, steal confidential information, establish persistent access, and facilitate subsequent stages of targeted attacks.
As geopolitics remains key driver for APT attacks, such actors remain among the most significant cyber risks in the region for businesses and governmental entities. To maximize persistence and evade detection, they continuously refine their toolsets, deploying increasingly sophisticated malware capable of maintaining long-term access to compromised systems while collecting valuable intelligence. In 2026, Kaspersky GReAT is tracking more than 20 APT groups actively targeting organizations across the META region.
Recent research by Kaspersky GReAT found the MuddyWater APT group targeting organizations across the Middle East during the Gulf conflict using previously unseen malware chains. The campaign employed custom loaders, injectors, previously unknown remote access trojans (RATs), credential stealers, and a modular data exfiltration framework, highlighting the group's rapid development of new tools to steal sensitive information and evade detection.
The increase in espionage activity is not limited to organizations. Individual are also increasingly targeted. Over the past year, attacks involving password stealers increased by 12% across the region. The stolen information can subsequently be used to hijack accounts, conduct follow-on attacks, extort victims, or sold to third parties on underground marketplaces.
Another rapidly growing trend is mobile cyberespionage. As smartphones increasingly store personal communications, corporate information, authentication credentials, and financial data, they have become high-value targets for attackers. Over the past year, the number of users targeted by mobile spyware increased by 65%, demonstrating that mobile devices are becoming one of the fastest-growing attack surfaces in the region.
‘Smartphones have become one of the most valuable sources of intelligence for cyberespionage actors. While Android devices continue to be widely targeted by mobile spyware, we are also observing an increasing number of reports of sophisticated campaigns targeting iOS, as demonstrated by Operation Triangulation and, more recently, Coruna attacks. These findings show that advanced mobile threats continue to evolve across both major platforms, making mobile security an essential part of cyber resilience for both organizations and individuals," said Dmitry Galov, Head of Global Research and Analysis Team, Russia and CIS, at Kaspersky.
As cyberespionage threats continue to evolve, Kaspersky recommends that organizations adopt a layered cybersecurity approach, combining continuous vulnerability management, timely patching, employee awareness training, threat intelligence, and advanced security solutions such as Kaspersky Next, which help detect sophisticated targeted attacks and protect organizations from long-term compromise.