Kenyan institutions are facing a growing cybersecurity threat, but the biggest danger may not lie in sophisticated new attack methods.
Instead, outdated software, weak security practices and failure to address known vulnerabilities continue to provide attackers with easy entry points.
This is according to the latest ESET Threat Report, which examines changes in the global threat landscape since December 2025 using data from ESET telemetry and analysis by its threat detection and research teams.
The report highlights the growing role of artificial intelligence (AI) in cybercrime, both as a target for attackers and as a tool for developing and executing attacks. ESET analysed about 900,000 AI skills and identified more than 3,000 that were outright malicious.
For Kenya, however, the report presents a more familiar picture. The cyber threats affecting local organisations largely mirror those seen internationally, with attackers relying on established techniques that continue to work because basic security measures are often left unattended.
“The threats facing Kenya are the same around the world, and email remains one of the most reliable ways of getting ransomware into the organisation,” says Allan Juma, Lead Cyber Security Engineer at ESET.
Email remains a major entry point
Malicious email attachments continue to play a significant role in cyber attacks globally and in Kenya.
According to the report, scripts accounted for 46.2 per cent of malicious email attachments, followed by Microsoft Office documents at 14.4 per cent, PDFs at 11.9 per cent and archive files at 9.7 per cent.
The continued popularity of these methods is largely explained by their effectiveness. Attackers can disguise malicious files as legitimate documents, invoices or other routine business communications, increasing the chances that employees will open them.
Another growing threat is QR code phishing, commonly known as “quishing”. Globally, about 11 per cent of detected phishing emails during the reporting period contained QR codes.
“QR codes have been adopted everywhere and are a convenience that attackers are counting on,” says Tony Anscombe, Chief Security Evangelist at ESET. “Many people still scan a QR code without stopping to consider where it leads.”
In Kenya, ESET telemetry recorded a 145 per cent increase in quishing between the second half of 2025 and the first half of 2026.
Kenya’s share of quishing activity remains below that of some major markets, including North America, where it accounted for 12.4 per cent of phishing emails. This suggests the technique still has significant room to expand locally.
Old vulnerabilities continue to expose systems
Perhaps the most significant lesson for Kenyan organisations comes from the continued exploitation of vulnerabilities that have been known for years.
Attempts to exploit CVE-2017-0199, a vulnerability affecting outdated Microsoft Office installations, more than doubled in Kenya between the second half of 2025 and the first half of 2026.
The vulnerability can allow malicious code to execute when a victim opens a specially crafted document. It is also among the frequently detected vulnerabilities globally and has reportedly been incorporated into commercially available attack frameworks such as GhostX.
The same concern extends to remote desktop infrastructure. Some systems remain exposed to the public internet, with certain endpoints running versions of Windows that are no longer supported and lacking basic security hardening.
“The key takeaway is to do the basics,” says Juma. “Patch your endpoints, protect them at a minimum standard, and stop using default ports and passwords. Too much of what we are seeing comes down to organisations not doing the fundamentals.”
Infostealers and fake ransomware attacks add to risks
Kenyan organisations are also seeing an increase in malware designed to steal sensitive information or deliver additional malicious programs.
ESET telemetry recorded a significant rise in Aotera, an infostealer and dropper that has become the fourth most frequently detected malware family in Kenya.
Aotera can be used to deliver other malware, including AgentTesla, Formbook, PureLogs, PhantomStealer and Vidar. Globally, AgentTesla and Formbook were the two most commonly detected infostealer families in the report, accounting for 12.1 per cent and 10.2 per cent respectively.
The findings also reveal another worrying trend: some Kenyan organisations are making payments in response to alleged ransomware attacks when no genuine ransomware is actually present.
Juma urged organisations to understand how ransomware operates and establish whether an attack is genuine before taking action.
“Organisations need to understand what ransomware is and how to verify a genuine attack before they respond to one,” he says.
The report recommends strengthening the basic cybercrime prevention measures such as regular patching, strong passwords, secure configurations, endpoint protection, controlled remote access and employee awareness to eliminate many of the weaknesses attackers continue to exploit.






