Residents of the United Arab Emirates (UAE) are advised to refrain from downloading mobile applications shared via WhatsApp, Telegram, and other unofficial channels. Experts warn that this practice is one of the most common and preventable ways malware can infiltrate personal devices.
During the Gisec Global 2026 event, Pushkar Singh, Head of Middle East and Africa at Protectt.AI, noted that the UAE ranks among the regions with the highest volume of application downloads globally, making it an attractive target for malware disguised as legitimate software.
Singh emphasized that the authentic source for Android device applications must be the Google Play Store, and for iOS, the App Store. He added that applications distributed through WhatsApp, Telegram, or the darknet often have compromised integrity, which users may not know until installation.
According to Singh, modern technologies are capable of detecting illegally obtained or modified applications and blocking their operation, even if an unaware employee has already installed them on a corporate device. He mentioned that some circulating applications have been 'reworked' with the introduction of malicious code, which his firm counters using code obfuscation and runtime protection tools.
Singh advised users not to attempt this themselves, but stressed that enterprises must implement security measures to prevent an application from functioning even if downloaded by an unsuspecting user. Beyond malicious apps, he drew attention to the sharp rise in social engineering using artificial intelligence, noting that voice and video cloning technology simplifies impersonation scams.
He warned that transactions authorized during a supposedly genuine video or voice call could be the result of scammers using AI-generated digital likenesses. Furthermore, Singh cautioned against the careless use of VPNs and proxy services without understanding traffic routing, as intercepted traffic is another common attack vector.
Singh noted that the rapidly growing fintech sector in the UAE and the wider Gulf Cooperation Council (GCC) region, largely based on AI-supported platforms, makes securing digital operations—whether P2P or enterprise-level—critically important. Regarding corporate security budgets, companies are increasingly viewing tools like runtime application self-protection and AI security as mandatory, rather than optional, given the financial and reputational consequences of breaches.
He recommended that companies choose security solutions based on task alignment, not just cost, extending protection beyond core applications to mobile endpoints and AI agents, over which enterprises often have limited direct control. Singh concluded that while AI brings immense benefits by creating efficiency, it also has a dark side when used to manipulate transactions or create new threats.
These concerns reflect a broader message from GISEC Global 2026, where Hadi Anwar, CEO of CPX, told Wam that AI-based threats are growing in speed, scale, and complexity, pushing organizations beyond traditional defense models. He cited deepfake fraud, identity-based attacks, and AI-driven social engineering as rising risks, alongside new issues such as unregulated AI use, data leakage, and model manipulation.
Anwar stated that generative AI has turned security into a business and governance issue, not just a technical one, requiring stricter oversight throughout the AI lifecycle and enhanced protection of third-party model-dependent data supply chains. He cited CPX's Sovereign Resilience Response—a combination of readiness, defense, automated containment, and rapid recovery—as an example of the shift towards proactive, evidence-based security models in a region where the highest demand at this year's event was seen in Secure AI, physical security, and OT security.
Ashraf Khoeil, Vice President of Sales for Meta and ANZ at Group-IB, reported that GCC countries have entered the top 10 global targets for supply chain attacks in 2025, and phishing attacks targeting the region's financial sector accounted for 28.5 percent of all such attacks in the Middle East and Africa. Khoeil explained that Group-IB's 'Prediction-First' approach relies on continuous monitoring of threat actors, compromised credentials, and malicious infrastructure, correlating this information with AI analysis to identify risks before they escalate into incidents. The company has conducted over 1,600 high-tech crime investigations worldwide since 2003 and supported 52 law enforcement agencies globally in 2025 in operations that led to 1,809 arrests and the dismantling of over 34,800 pieces of malicious infrastructure. He emphasized that threats are increasingly moving beyond the company perimeter, affecting suppliers, fintech partners, and payment providers, underscoring the value of local expertise.
