
Kenyan organizations are facing a rise in cyber threats as attackers continue to exploit familiar weaknesses, including outdated software, phishing emails and poorly secured remote access systems, according to the latest ESET Threat Report.
ESET telemetry revealed that cybercriminals are increasingly using established attack methods rather than relying solely on sophisticated new techniques. In Kenya, the continued exploitation of old vulnerabilities is raising concerns about basic cybersecurity practices across organizations.
One of the biggest surges was recorded in QR-code phishing, with ESET detecting a 145% increase in quishing activity in Kenya between the second half of 2025 and the first half of 2026.
The technique uses QR codes to direct victims to malicious websites, with attackers often exploiting the fact that users may scan codes on their phones, outside some of their organization’s security controls.
Globally, about 11% of detected phishing emails during the reporting period contained QR codes, demonstrating the growing use of the technique by cybercriminals.
“The threats facing Kenya are the same around the world, and email remains one of the most reliable ways of getting ransomware into the organisation,” said Allan Juma, Lead Cyber Security Engineer at ESET.
Malicious email attachments remain a major delivery mechanism. Scripts accounted for 46.2% of malicious attachments globally, followed by Microsoft Office documents at 14.4%, PDFs at 11.9% and archives at 9.7%.
ESET also recorded more than a twofold increase in exploitation attempts targeting CVE-2017-0199 in Kenya between H2 2025 and H1 2026. The vulnerability affects outdated Microsoft Office installations and can allow malicious code to execute when a victim opens a specially crafted document.
Juma added that organizations should prioritise basic security measures such as patching endpoints, securing remote access and replacing default ports and passwords.
Meanwhile, ESET reported a significant increase in detections of Aotera, an infostealer and dropper that has become the fourth most detected malware family in Kenya. It has been used to deliver other malware, including AgentTesla, Formbook, PureLogs, PhantomStealer and Vidar.
ESET further warned that some organisations have been making payments in response to suspected ransomware incidents without first establishing whether their systems have actually been encrypted by genuine ransomware.
The latest threat data suggests that closing these basic security gaps could be as important as investing in new cybersecurity technologies, as attackers continue to exploit weaknesses that organisations already know how to fix.
Download the FREE Kaspersky Next Enterprise Security Guide here to explore the complete framework for simplifying security operations and building cyber resilience.
Go to TECHTRENDSKE.co.ke for more tech and business news from the African continent and across the world.
Follow us on WhatsApp, Telegram, Twitter, and Facebook, or subscribe to our weekly newsletter to ensure you don’t miss out on any future updates. Send tips to editorial@techtrendsmedia.co.ke



