By Admin,
Despite growing investments in cybersecurity technologies, human behaviour continues to provide cybercriminals with one of the easiest entry points into digital systems.
This is the key takeaway from new research by Kaspersky Digital Footprint Intelligence (DFI), which found that 35 per cent of infostealer malware infections begin when users execute files directly from temporary download folders on their devices.
The findings, based on an analysis of five million infostealer log files discovered on the dark web in 2025, suggest that many cyberattacks succeed not because of sophisticated hacking techniques, but because users unknowingly initiate the infection process themselves.
Infostealers are among the fastest-growing categories of cyber threats globally. Designed to harvest passwords, browser cookies, cryptocurrency wallet information and other sensitive data, these malware strains have become a lucrative tool for cybercriminals targeting both individuals and organisations.
According to Kaspersky, the Windows temporary directory accounted for the largest share of observed infections. The folder is commonly used to store files downloaded from the internet before users save or install them.
The data indicates that many users are bypassing basic cybersecurity precautions and running downloaded files immediately, creating opportunities for attackers to distribute malicious software disguised as legitimate applications, software activators or gaming tools.
Interestingly, the report found that only 32 per cent of infections involved advanced malware techniques such as process injection and “living-off-the-land” attacks, where cybercriminals abuse trusted system processes to evade detection.
This suggests that social engineering and user manipulation remain more effective than technical sophistication in many cybercrime operations.
“Infostealers increased by 59 per cent year-on-year in 2025. In many cases, attackers do not need sophisticated techniques; they simply need to convince a user to run a file,” said Sergey Shcherbel, Expert at Kaspersky Digital Footprint Intelligence.
For businesses undergoing digital transformation, the findings highlight an important reality: cybersecurity is no longer solely a technology challenge but also a human challenge.
As organisations expand cloud adoption, remote work environments and digital services, employee awareness and cyber hygiene are becoming just as important as firewalls, endpoint protection and threat intelligence platforms.
For African markets experiencing rapid digitalisation, the implications are significant. Increased internet penetration, growing digital payment adoption and expanding e-commerce ecosystems are creating larger attack surfaces for cybercriminals seeking access to consumer and enterprise data.
Kaspersky recommends downloading software only from trusted sources, avoiding pirated applications, maintaining updated security tools and enabling multi-factor authentication wherever possible.
As cybercriminals continue to refine their tactics, the latest findings serve as a reminder that even the most advanced security infrastructure can be undermined by a single click.
