

Distributed denial-of-service (DDoS) attacks targeting the UAE are increasingly taking a quieter approach, with 91% of incidents recorded in the country classified as low-volume, according to recent reports. Rather than relying only on massive traffic floods designed to overwhelm networks, attackers are increasingly using smaller campaigns that can be harder to detect and investigate.
The shift reflects a broader change in the cyber threat landscape, with attackers testing defenses and looking for weak points before attempting more disruptive operations.
Low-volume DDoS attacks can generate considerably less traffic than traditional large-scale floods, allowing them to remain below some organizations’ detection thresholds. Attackers can use these campaigns to probe networks, test security controls and identify vulnerable services.
Recent regional data from cybersecurity firm StormWall also shows probing attacks across the Middle East and North Africa increased by 122% year on year in the second quarter of 2026. The UAE accounted for 27% of regional DDoS activity during the period, making it the most targeted country in the region.
The UAE recorded a 268% year-on-year increase in DDoS activity during the quarter, according to StormWall.
The changing nature of attacks is not limited to their size. StormWall reported a 148% annual increase in multi-vector DDoS campaigns across MENA during the second quarter. Such operations can combine different attack methods or switch between targets and techniques, making them more difficult for security teams to contain.
The average botnet used in regional campaigns also grew substantially, while attack campaigns lasted longer than they did a year earlier. Politically motivated groups were responsible for much of the activity recorded in the region, with hacktivists accounting for 83% of DDoS incidents in StormWall’s Q2 dataset.
“The future of DDoS is not defined by volume, but by precision,” said Gaurav Srivastava, Director of Managed Security Controls at Help AG, the cybersecurity arm of e&. “As attacks become more distributed, persistent and adaptive, organizations are being challenged not only to keep services online, but to maintain performance, availability and user trust under pressure,” Srivastava added.
Also Read: Cyber Security Council Urges Vigilance Against Human Error Amid 800,000 Daily Attacks
Government agencies, banks, telecommunications companies and other digitally dependent organizations remain attractive targets. Separate research from Positive Technologies identified the UAE as one of the Gulf's most targeted countries during the first half of 2026, while noting that DDoS activity had declined from its peak during the most intense phase of regional conflict.
For organizations, the growing presence of low-volume and probing attacks means monitoring only major traffic spikes may no longer be sufficient. Security teams increasingly need to watch for unusual traffic patterns, repeated connection attempts and other signs that attackers may be testing their defenses.
The trend highlights how DDoS campaigns are evolving from highly visible disruption attempts into more persistent and carefully measured operations.