ISLAMABAD – Turkiye and Kenya had the highest number of users affected by web incidents (online threats) in the region during the first quarter of 2025.
According to the Kaspersky Global Research and Analysis Team, these countries were followed by Qatar, Nigeria and South Africa.
Saudi Arabia had the lowest while Pakistan had the second lowest share of users attacked by web born threats in the META region during Q1 2025.
Kaspersky experts constantly track highly sophisticated attacks. Specifically, they are monitoring 25 APT groups currently active in the META region, including such well-known ones as SideWinder, Origami Elephant, MuddyWater. The rise of creative exploits for mobile and further development of techniques aimed at evading detection are among the trends Kaspersky is seeing in these targeted attacks.
Ramsomware remains one of the most destructive cyberthreats. According to Kaspersky data, the share of users affected by ransomware attacks increased by 0.02 p.p to 0.44% from 2023 to 2024 globally. In the Middle East the growth is 0.07 p.p. to 0.72%, in Africa: 0.01 p.p. growth to 0.41%, in Turkiye 0,06 p.p. growth to 0.46%. Attackers often don’t distribute this type of malware on a mass scale, but prioritize high-value targets.
In 2025, ransomware is expected to evolve by exploiting unconventional vulnerabilities. The proliferation of LLMs tailored for cybercrime will also further amplify ransomware’s reach and impact. LLMs marketed on the dark web lower the technical barrier to creating malicious code, phishing campaigns and social engineering attacks, allowing even less skilled actors to craft highly convincing lures or automate ransomware deployment.
“Ransomware is one of the most pressing cybersecurity threats facing organizations today, with attackers targeting businesses of all sizes and across every region, including META. Ransomware groups continue to evolve by adopting techniques, such as developing cross-platform ransomware, embedding self-propagation capabilities and even using zero-day vulnerabilities that were previously affordable only for APT actors,” said Sergey Lozhkin, Head of META and APAC regions in Global Research and Analysis Team at Kaspersky. “To stay secure, organizations need a layered defense: up-to-date systems, network segmentation, real-time monitoring, robust backups, and continuous user education”.