{"id":2637,"date":"2024-03-01T06:00:00","date_gmt":"2024-03-01T06:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/ai-powered-threats-cyberattacks-on-infrastructure-pummel-africa"},"modified":"2024-03-01T06:00:00","modified_gmt":"2024-03-01T06:00:00","slug":"infrastructure-cyberattacks-ai-powered-threats-pummel-africa","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/03\/01\/infrastructure-cyberattacks-ai-powered-threats-pummel-africa\/","title":{"rendered":"Infrastructure Cyberattacks, AI-Powered Threats Pummel Africa"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blta774399a3328f72d\/65ca92eb3900f2040ac3f04a\/cg_alex-africa-centered-globe-shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/infrastructure-cyberattacks-ai-powered-threats-pummel-africa.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/infrastructure-cyberattacks-ai-powered-threats-pummel-africa.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Most major economies in Africa experienced fewer overall cyber threats in 2023, but there were some dramatic exceptions: Kenya suffered a 68% rise in <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/ransomware-as-a-service-spawns-widespread-cyberattacks-in-mea\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">ransomware attacks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, while South Africa saw a 29% jump in phishing attacks targeting sensitive information.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The overall trend is one of change. Cyber attackers are increasingly targeting critical infrastructure in Africa and experimenting with ways to incorporate artificial intelligence into their toolkits, according to telemetry data from Kaspersky. Threat actors are now routinely abusing AI large language models (LLMs) to create more convincing social engineering attacks and to quickly produce the lures for such attacks in a variety of languages, says Maher Yamout, lead security researcher at Kaspersky&#8217;s threat research group.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;As more advanced technologies become available, cybercriminals will use these to help them become more effective in their cybercriminal tactics and strategies,&#8221; he says. &#8220;We have seen how the cyber threat landscape continues to evolve, becoming somewhat different every year.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Africa historically has been a source of pervasive social engineering threats, including a &#8220;high concentration of BEC (business email compromise) actors&#8221; such as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/interpol-operation-delilah-bec-arrest\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">the SilverTerrier group<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, according to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/cybilportal.org\/publications\/african-cyberthreat-assessment-report-2023-cyberthreat-trends\/\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">Interpol&#8217;s African Cyberthreat Assessment 2023 report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Citizens in Africa and the META region (Middle East, Turkey, and Africa) as a whole are increasingly becoming the targets of cybercriminals, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/kaspersky.africa-newsroom.com\/press\/kaspersky-shares-cyberthreat-landscape-insights-for-the-african-region?lang=en\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">according to Kaspersky&#8217;s report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Currently, BEC attacks remain the primary cyber threat to organizations and individuals, with the financial, telecom, government, and retail sectors accounting for more than half of all attacks, according to a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.ptsecurity.com\/ww-en\/analytics\/africa-cybersecurity-threatscape-2022-2023\/\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">2023 Positive Technologies report on threats to the Africa region<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Eighty percent of attacks on African organizations involved malware, while 91% of attacks on African citizens included a social engineering component, the report stated.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;To effectively combat cyber threats, African organizations should invest in the development of their cybersecurity experts,&#8221; Positive Technologies stated in its report. &#8220;Regular training and certification of cybersecurity employees will enhance their skills and knowledge, boosting the company with expert support in preventing and responding to cyberattacks.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"AI Promises Benefits, Threats\">AI Promises Benefits, Threats<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One reason for the rise in attacks against organizations in this region is the use of AI technologies such as LLMs, which have lowered the bar to entry for would-be cybercriminals and professional groups alike, Kaspersky&#8217;s Yamout says. The security vendor has seen signs of AI creating more convincing phishing email messages, synthetic identities, and deepfakes of real people, according to Yamout.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">These cyber threats reinforce and worsen the historical inequities of AI, which include poor facial recognition of African citizens leading to unequal and unfair treatment; financial fraud powered by massive datasets collected from consumers; and AI-powered targeting, according to an <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/afripoli.org\/ai-in-africa-key-concerns-and-policy-considerations-for-the-future-of-the-continent\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">analysis by the Africa Policy Research Institute<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;AI technologies pose real and potential threats to the societies involved in their design and construction and to those where the technologies are tested and used,&#8221; Rachel Adams, a principal researcher at Research ICT Africa, stated in the analysis.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Hacking Critical Infrastructure\">Hacking Critical Infrastructure<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The adoption of operational technology to automate critical infrastructure systems is also under attack in Africa, with more than a third of OT computers (38%) encountering at least one threat in the second half of 2023, Kaspersky&#8217;s Yamout says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The source of attacks continues to be a mix of cybercriminals and nation-state groups. But as economic, political, and climate tensions rise, hacktivism has increased, he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;In addition to country-specific protest movements, the rise of cosmo-political hacktivism is expected, driven by socio-cultural and macro-economic agendas such as eco-hacktivism,&#8221; Yamout says. &#8220;This diversification of motives may contribute to a more complex and challenging threat landscape.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Mobile Internet, Mobile Threats\">Mobile Internet, Mobile Threats<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Mobile devices are the primary way Africans access the Internet, so mobile threats continue to rise, according to Kaspersky. In 2023, the company saw a 10% increase in threats directed at mobile devices across the continent, with a rise in mobile ransomware and credential-seeking SMS phishing attacks becoming more common, Yamout says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The rise in remote work globally has also contributed to the rise in mobile threats. While Africa lags behind in remote work, 42% of employees on the continent work offsite at least once per week, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.weforum.org\/agenda\/2022\/03\/3-ways-africa-remote-working\/\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">according to the World Economic Forum<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Protecting these mobile employees represents more of a challenge for organizations, Yamout says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;At a time when hybrid work has been normalized across the world, enterprises must also assess the potential privacy and security risks with employees being virtual,&#8221; he says. &#8220;To this end, they must implement best practices when it comes to safeguarding personal and corporate data.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Kaspersky urges organizations to patch software and devices, manage credentials and identities more closely, and focus on locking down endpoints.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">At present, the exploitation of unpatched software, vulnerable Web services, and weak remote access services are the most common ways that ransomware groups are gaining access to their victims in Africa, according to the firm.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/ai-powered-threats-cyberattacks-on-infrastructure-pummel-africa\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Most major economies in Africa experienced fewer overall cyber threats<\/p>\n","protected":false},"author":12,"featured_media":2638,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2637","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/infrastructure-cyberattacks-ai-powered-threats-pummel-africa.jpg?fit=1600%2C900&ssl=1",1600,900,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/infrastructure-cyberattacks-ai-powered-threats-pummel-africa.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/infrastructure-cyberattacks-ai-powered-threats-pummel-africa.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/infrastructure-cyberattacks-ai-powered-threats-pummel-africa.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/infrastructure-cyberattacks-ai-powered-threats-pummel-africa.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/infrastructure-cyberattacks-ai-powered-threats-pummel-africa.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/infrastructure-cyberattacks-ai-powered-threats-pummel-africa.jpg?fit=1600%2C900&ssl=1",1600,900,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/infrastructure-cyberattacks-ai-powered-threats-pummel-africa.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/infrastructure-cyberattacks-ai-powered-threats-pummel-africa.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/infrastructure-cyberattacks-ai-powered-threats-pummel-africa.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/infrastructure-cyberattacks-ai-powered-threats-pummel-africa.jpg?fit=1600%2C900&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2637","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2637"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2637\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2638"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2637"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2637"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2637"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}