{"id":5629,"date":"2024-10-04T07:27:36","date_gmt":"2024-10-04T12:27:36","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/criminals-test-ransomware-africa"},"modified":"2024-10-04T07:27:36","modified_gmt":"2024-10-04T12:27:36","slug":"criminals-are-testing-their-ransomware-campaigns-in-africa","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/10\/04\/criminals-are-testing-their-ransomware-campaigns-in-africa\/","title":{"rendered":"Criminals Are Testing Their Ransomware Campaigns in Africa"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltbdbb16f93949066d\/66fc9c52acd55682feb2a025\/africacode-Skorzewiak-alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/criminals-are-testing-their-ransomware-campaigns-in-africa.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/criminals-are-testing-their-ransomware-campaigns-in-africa.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The industry consensus about <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/ransomware-reaches-new-heights\" rel=\"noopener\">ransomware<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> is that it&#8217;s not going away anytime soon, evidenced by the consistent <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/blackhat-2024-ransomware-gangs-profits-continue-grow\" rel=\"noopener\">growth of ransomware attacks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> over the past decade. We&#8217;ve seen some of the biggest ransomware attacks in history \u2014 including the JBS, Colonial Pipeline, and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/5-years-after-the-equifax-breach-industry-experts-share-new-insights\" rel=\"noopener\">Equifax breaches<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 over the last five years. What&#8217;s more, between 2023 and 2024, there was an 81% year-on-year jump in the number of recorded ransomware attacks, according to cybersecurity research firm <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cybersecuritydive.com\/press-release\/20240501-black-kite-research-reveals-growing-persistence-sophistication-and-aggress\/#:~:text=According%20to%20the%20Black%20Kite,targeted%20country%20in%20the%20world.\" rel=\"noopener\">Black Kite<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And according to a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"http:\/\/darkreading.com\/cybersecurity-operations\/new-research-suggests-africa-is-being-used-as-a-testing-ground-for-nation-state-cyber-warfare?utm_source=pocket_shared\" rel=\"noopener\">report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> earlier this year by cybersecurity research firm Performanta, ransomware gangs have a new strategy: Ransomware-as-a-Service (RaaS) organizations are focusing on African nations as initial targets for nation-state attacks before launching malicious campaigns in more developed climes.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But what makes Africa a choice destination for these so-called &#8220;RaaS gangs,&#8221; and what does this mean for the burgeoning economies on the continent?<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Why Africa?\">Why Africa?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The booming economies of Africa, rich in natural resources and brimming with potential, are attracting not just investors, but also cybercriminals. Performanta&#8217;s report, which shows that Africa is increasingly becoming a testing ground for ransomware attacks, raises serious concerns for the continent&#8217;s future and underscores the urgent need for collaboration between African states, corporations, and the West.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One draw for the cyber gangs is the continent&#8217;s overall low levels of cybersecurity strategy at the national level. In the 2024 edition of the United Nations International Telecommunication Union&#8217;s <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.itu.int\/en\/ITU-D\/Cybersecurity\/Pages\/global-cybersecurity-index.aspx\" rel=\"noopener\">Global Cybersecurity Index<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, only nine out of 44 countries in Africa qualified for the first or second tier of cybersecurity maturity. While this is an improvement over the previous report&#8217;s rankings, that still leaves swathes of the continent less prepared.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Funsho Richard, a senior cybersecurity analyst and consultant, agrees with Performanta&#8217;s findings. &#8220;Africa&#8217;s potential for profitable attacks amidst its digital growth is a magnet for cybercriminals,&#8221; he says. Ransomware gangs and nation-state actors are exploiting the continent&#8217;s weaker cybersecurity defenses to refine their methods in a &#8220;lower-risk environment&#8221; before launching attacks on better-secured developed nations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This approach makes perfect sense from the attackers&#8217; perspective. As Gal Nakash, co-founder and CPO at identity-based SaaS security company Reco, explains, &#8220;Building a sophisticated testing environment for a campaign is challenging. Leveraging less interesting or poorly secured victims is more effective and increases the likelihood of remaining undetected by security tools.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In June, South Africa&#8217;s National Health Laboratory Service (NHLS) <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/therecord.media\/south-africa-lab-ransomware-mpox-outbreak\" rel=\"noopener\">confirmed<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> it was dealing with a ransomware attack that significantly affected the dissemination of lab results as the country responds to an outbreak of mpox (previously known as monkeypox). The NHLS runs 265 laboratories across South Africa that provide testing services for public healthcare facilities in the country&#8217;s nine provinces. The spokesperson declined to say which ransomware group was behind the incident or whether a ransom was paid.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Signs and Guardrails\">Signs and Guardrails<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So, how can African businesses identify these potential &#8220;ransomware testing&#8221; campaigns? Richard points out that, unlike traditional ransomware attacks that target specific industries like finance or energy, these campaigns might target a wider range of businesses.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Traditionally, ransomware gangs have a well-defined appetite: high-value sectors like finance, manufacturing, and energy. A recent surge in attacks targeting a wider range of businesses across various industries in Africa could be a red flag, indicating a testing campaign in progress. Performanta&#8217;s research also validates this concern. The report reveals a &#8220;large increase in financial\/banking trojans with a 59% increase in Kenya and a 32% increase in Nigeria across a single quarter,&#8221; suggesting gangs are casting a wider net.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Performanta&#8217;s report suggests African organizations may not be fully prepared for this shift in attack tactics. While Nakash expresses confidence in the capabilities of modern cybersecurity solutions like extended detection and response\/endpoint detection and response (XDR\/EDR), he acknowledges a lack of widespread adoption. But he says that businesses that regularly update their cybersecurity controls and policies can stop attackers dead in their tracks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This includes maintaining visibility into their entire network environment, encompassing cloud, SaaS (Software-as-a-Service), on-premises infrastructure, and all the applications they use daily. Critical applications should be mapped, and robust policies and alert notifications should be set up to identify and address any violations or misconfigurations that could create potential security vulnerabilities,&#8221; Nakash says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, to spot the wider trend of test campaigns requires national coordination and strategy, as well as regional cooperation. The Africa Center for Strategic Studies cites several regional initiatives, such as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/african-cybercrime-operations-taken-down-in-joint-interpol-afripol-effort\" rel=\"noopener\">Afripol<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, but warns that only <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/africacenter.org\/spotlight\/african-lessons-in-cyber-strategy\/\" rel=\"noopener\">17 countries on the continent<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> even have a national cybersecurity strategy.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Building a Strong Defense\">Building a Strong Defense<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">What businesses on the continent need to stay cyber safe is a foundational approach \u2014 doing the basic things the right way. &#8220;Organizations need thorough visibility into their entire network environment, including cloud and on-premises infrastructure,&#8221; Nakash says. Ensuring that all configurations adhere to best security practices and setting up alert notifications for any suspicious activity are essential steps to prevent potential threats.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The fight against cybercrime requires a united front. Guy Golan, executive chairman and CEO at Performanta, emphasizes this point, noting, &#8220;The West and Africa must implement long-term collaborative efforts to build a strong defense against this threat.&#8221; By sharing knowledge, resources, and best practices, both continents can work together to create a more secure digital landscape for all.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Building resilience against these attacks isn&#8217;t just about protecting individual businesses; it&#8217;s about safeguarding the future of Africa&#8217;s booming digital economy. &#8220;The solution lies in long-term collaborative efforts. Only then can we effectively combat this growing threat,&#8221; says Richard.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The use of Africa as a testing ground for ransomware attacks is a troubling development that shows the need for enhanced cybersecurity measures across the continent. By understanding the trends and characteristics of these attacks, businesses can better prepare and protect themselves. Collaboration between nations, coupled with the adoption of advanced security technologies, is key in combating the growing global threat of ransomware.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/criminals-test-ransomware-africa\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The industry consensus about ransomware is that it&#8217;s not going<\/p>\n","protected":false},"author":12,"featured_media":5630,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5629","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/criminals-are-testing-their-ransomware-campaigns-in-africa.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/criminals-are-testing-their-ransomware-campaigns-in-africa.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/criminals-are-testing-their-ransomware-campaigns-in-africa.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/criminals-are-testing-their-ransomware-campaigns-in-africa.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/criminals-are-testing-their-ransomware-campaigns-in-africa.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/criminals-are-testing-their-ransomware-campaigns-in-africa.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/criminals-are-testing-their-ransomware-campaigns-in-africa.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/criminals-are-testing-their-ransomware-campaigns-in-africa.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/criminals-are-testing-their-ransomware-campaigns-in-africa.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/criminals-are-testing-their-ransomware-campaigns-in-africa.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/criminals-are-testing-their-ransomware-campaigns-in-africa.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5629","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5629"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5629\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5630"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5629"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5629"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5629"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}