Distributed denial of service (DDoS) attacks across the Middle East and North Africa (MENA) increased significantly during the first half of 2026, highlighting growing cybersecurity risks for the region’s expanding digital economy. According to a new report from StormWall, a developer of DDoS protection solutions, attack volumes across the region rose by 178 percent year on year between January 1 and June 30, 2026. The report also found that the average bandwidth generated by attacks increased by 300 percent, indicating that threat actors are gaining access to larger and more powerful attack capabilities. StormWall said the findings are based on attacks mitigated for its MENA customers during the period and reflect the continued growth of botnet infrastructure used to generate high volume malicious traffic.
One of the key trends identified in the report was the rapid expansion of botnet networks across MENA. StormWall found that the average number of devices involved in botnet driven attacks tripled during the first half of 2026, increasing from approximately 12,000 devices during the same period in 2025 to around 36,000 devices. Larger and more distributed botnets allow attackers to generate higher levels of traffic while changing source locations and maintaining longer campaigns against targeted organisations. The report noted that cybercriminal groups are also increasingly using DDoS for hire services, allowing a wider range of actors to access attack capabilities without needing to create their own infrastructure. Although authorities and security teams have disrupted major botnets including Aisuru and Kimwolf, StormWall said attack capacity has continued shifting toward emerging networks such as Masjesu/XorBot, xlabs_v1 and RapperBot/Eleven11bot. The company also identified more than 116 active variants of the Mirai malware family during the reporting period.
The nature of DDoS campaigns is also becoming more complex, with attackers increasingly combining multiple techniques in individual operations. StormWall recorded a 136 percent year on year increase in multi vector DDoS attacks across MENA during the first half of 2026. These attacks use multiple methods to overwhelm systems and can change techniques during an ongoing campaign, creating additional challenges for security teams responsible for maintaining service availability. Instead of relying only on large traffic volumes, attackers are increasingly using adaptive approaches designed to test security controls and bypass traditional defence mechanisms. The United Arab Emirates recorded the highest share of DDoS attacks in the region, accounting for 27 percent of incidents monitored by StormWall, followed by Saudi Arabia at 17 percent and Iran at 12 percent. The company linked higher attack activity in these markets to rapid digital transformation, increased availability of online services and the growing importance of digital platforms across business and government operations.
Financial services were the most targeted sector in the region, representing 16 percent of DDoS attacks recorded by StormWall. Transportation organisations, including logistics and mobility companies, accounted for 10 percent of attacks, while retail businesses represented 4 percent. These sectors remain attractive targets because service interruptions can directly affect customers, transactions and business operations. StormWall founder and CEO Ramil Khantimirov said the increase in attack bandwidth means organisations across MENA must prepare for significantly larger volumes of malicious traffic. He said modern botnets can coordinate tens of thousands of active devices and use wider ecosystems containing millions of compromised systems to launch large scale campaigns. According to StormWall, organisations need automated detection capabilities, sufficient traffic filtering capacity and security systems capable of identifying malicious activity while allowing legitimate users to continue accessing services.
The findings come as countries across MENA continue expanding cloud infrastructure, digital financial platforms, e-commerce services and connected technologies. While these developments are supporting economic growth and digital transformation, they are also increasing the number of systems requiring continuous protection. StormWall said its analysis was conducted using data from attacks mitigated through its globally distributed DDoS protection network, which includes dedicated points of presence in the Middle East. The company stated that its infrastructure provides more than 8 Tbit/s of filtering capacity to help defend organisations against different types of DDoS attacks and track changing threat patterns across industries. As digital services become more central to regional economies, the report suggests that organisations will need stronger resilience measures, continuous monitoring and scalable protection strategies to address attacks that are becoming larger, more distributed and increasingly complex.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.