ESET: nine-year Office flaw doubled in Kenya; QR phishing up 145%
Key points
- ESET says Kenyan detections of CVE-2017-0199, a 2017 Microsoft Office bug, more than doubled between H2 2025 and H1 2026.
- QR-code phishing (“quishing”) jumped 145% in Kenya over the same window; ESET calls that figure directional. About 11% of phishing mails globally carried a QR code.
- Aotera is now the fourth-most detected malware family in Kenya, used to drop AgentTesla, Formbook and others.
- Engineer Allan Juma: patch, drop default ports/passwords; some firms treated non-ransomware incidents as ransomware.
The hole in Microsoft Office is nine years old and still paying rent in Kenyan inboxes. ESET’s H1 2026 Threat Report says detections of CVE-2017-0199 here more than doubled from the second half of 2025 to the first half of 2026, The Standard reported.
The bug runs code when someone opens a crafted document and now ships inside kits such as GhostX sold on dark-web markets. QR-code phishing, or “quishing,” jumped 145 per cent in Kenya in the same span — ESET says treat that as directional because the baseline is incomplete. Globally about 11 per cent of phishing emails in the period carried a QR code, often pushing the victim onto a phone outside the office filter. Kenya sits just under North America’s 12.4 per cent. Chief security evangelist Tony Anscombe said attackers count on people scanning first. Scripts were 46.2 per cent of malicious attachments worldwide, then Office files 14.4 per cent, PDFs 11.9 per cent, archives 9.7 per cent. Locally, the Aotera family is now the fourth-most seen, used to drop stealers including AgentTesla, Formbook, PureLogs, PhantomStealer and Vidar. Lead engineer Allan Juma also flagged internet-exposed remote-access boxes on unsupported Windows. His line: patch, harden, stop default ports and passwords. Some Kenyan organisations, he said, responded as if ransomware had hit when it had not. The same report counted more than 3,000 malicious AI “skills” among about 900,000 scanned worldwide.
A 2017 CVE is a choice, not a mystery
If a nine-year patch still doubles, the story is unpatched endpoints, not a new Kenyan genius attacker. Boards should ask for CVE-2017-0199 close-out dates, not another awareness poster.
Technology desk: Technology. Verified CVE, 145% quishing, Aotera rank and Juma/Anscombe quotes from The Standard / ESET H1 2026.
ICT Authority and CA should say whether government mail still allows un-sandboxed Office macros. Firms should disable QR-in-email at the gateway.
Staff should not scan a code from a PDF on a work phone until the helpdesk has a written allow-list.
Readers should cross-check any deadline, fee, court date or programme claim against primary gazettes, agency circulars and court records before acting on this report.
Official gazettes, court rulings and agency circulars may update these facts after publication; readers should verify any deadline, fee or court date against primary sources before acting.
Based on The Standard reporting of ESET’s H1 2026 Kenya findings. Vendor telemetry is not a national census.