Distributed denial-of-service (DDoS) attacks in the Middle East and North Africa (Mena) surged by 178 per cent year-on-year in the first half of 2026, according to a new report by cybersecurity firm StormWall.
The report highlights a sharp escalation in attack scale, with average attack bandwidth jumping 300pc compared to H1 2025. Experts attribute the spike to expanding global and regional botnet networks, where hijacked devices are rented out via commercial DDoS-for-hire platforms.
Consequently, the average number of compromised devices used per attack in the Mena region tripled from 12,000 to 36,000. Following global law enforcement operations targeting major botnets like Aisuru and Kimwolf, attack traffic rapidly migrated to expanding variants such as Masjesu/XorBot, RapperBot/Eleven11bot, and over 116 active Mirai strains.
Tactics also grew more complex, with multi-vector campaigns – where attackers blend and switch methods mid-assault – rising by 136pc year-on-year.
The UAE was the most targetted country in the region, absorbing 27pc of all recorded attacks, followed by Saudi Arabia at 17pc and Iran at 12pc. Analysts linked this focus to rapid digital transformation, high-value online service offerings, and ongoing regional geopolitical tensions.
By industry, financial services took the brunt of the onslaught, accounting for 16pc of targetted attacks, followed by transport and logistics at 10pc, and retail at 4pc.
“The rapid growth in attack bandwidth means regional organisations are facing a major increase in malicious traffic volume,” said StormWall founder and chief executive Ramil Khantimirov. “Modern botnets can co-ordinate tens of thousands of devices to launch sudden multi-terabit attacks, making automated detection and always-on scrubbing capacity essential.”
The findings are based on threat telemetry mitigated across StormWall’s global scrubbing network, which maintains a filtering capacity exceeding 8 Tbit/s, including dedicated points of presence in the Middle East.
A distributed denial-of-service attack is a malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic.
DDoS attacks achieve effectiveness by utilising multiple compromised computer systems as sources of attack traffic. Exploited machines can include computers and other networked resources such as IoT devices.
avinash@gdnmedia.bh