Telecom
Key Trends in Sophos 2022 Threat Report

Sophos, a global leader in next-generation cybersecurity, on Wednesday published the Sophos 2022 Threat Report, which shows how the gravitational force of ransomware’s black hole is pulling in other cyberthreats to form one massive, interconnected ransomware delivery system – with significant implications for IT security.

The report, written by SophosLabs security researchers, Sophos Managed Threat Response threat hunters and rapid responders, and the Sophos AI team, provides a unique multi-dimensional perspective on security threats and trends facing organizations in 2022.
The Sophos 2022 Threat Report analyzes the following key trends:
1. Over the coming year, the ransomware landscape will become both more modular and more uniform, with attack “specialists” offering different elements of an attack “as-a-service” and providing playbooks with tools and techniques that enable different adversary groups to implement very similar attacks.
According to Sophos researchers, attacks by single ransomware groups gave way to more ransomware-as-a-service (RaaS) offerings during 2021, with specialist ransomware developers focused on hiring out malicious code and infrastructure to third-party affiliates.
Some of the most high profile ransomware attacks of the year involved RaaS, including an attack against Colonial Pipeline in the U.S. by a DarkSide affiliate.
An affiliate of Conti ransomware leaked the implementation guide provided by the operators, revealing the step-by-step tools and techniques that attackers could use to deploy the ransomware.
Once they have the malware they need, RaaS affiliates and other ransomware operators can turn to Initial Access Brokers and malware delivery platforms to find and target potential victims. This is fueling the second big trend anticipated by Sophos.
2. Established cyberthreats will continue to adapt to distribute and deliver ransomware. These include loaders, droppers and other commodity malware; increasingly advanced, human-operated Initial Access Brokers; spam; and adware. In 2021, Sophos reported on Gootloader operating novel hybrid attacks that combined mass campaigns with careful filtering to pinpoint targets for specific malware bundles.
3. The use of multiple forms of extortion by ransomware attackers to pressure victims into paying the ransom is expected to continue and increase in range and intensity. In 2021, Sophos incident responders catalogued 10 different types of pressure tactics, from data theft and exposure, to threatening phone calls, distributed denial of service (DDoS) attacks, and more.
4. Cryptocurrency will continue to fuel cybercrimes such as ransomware and malicious cryptomining, and Sophos expects the trend will continue until global cryptocurrencies are better regulated. During 2021, Sophos researchers uncovered cryptominers such as Lemon Duck and the less common, MrbMiner, taking advantage of the access provided by newly reported vulnerabilities and targets already breached by ransomware operators to install cryptominers on computers and servers.
“Ransomware thrives because of its ability to adapt and innovate,” said Chester Wisniewski, principal research scientist at Sophos. “For instance, while RaaS offerings are not new, in previous years their main contribution was to bring ransomware within the reach of lower-skilled or less well-funded attackers.
This has changed and, in 2021, RaaS developers are investing their time and energy in creating sophisticated code and determining how best to extract the largest payments from victims, insurance companies, and negotiators. They’re now offloading to others the tasks of finding victims, installing and executing the malware, and laundering the pilfered cryptocurrencies.
This is distorting the cyberthreat landscape, and common threats, such as loaders, droppers, and Initial Access Brokers that were around and causing disruption well before the ascendancy of ransomware, are being sucked into the seemingly all-consuming ‘black hole’ that is ransomware.
“It is no longer enough for organizations to assume they’re safe by simply monitoring security tools and ensuring they are detecting malicious code. Certain combinations of detections or even warnings are the modern equivalent of a burglar breaking a flower vase while climbing in through the back window.
“Defenders must investigate alerts, even ones which in the past may have been insignificant, as these common intrusions have blossomed into the foothold necessary to take control of entire networks.”
Additional trends Sophos analyzed include:
· After the ProxyLogon and ProxyShell vulnerabilities were discovered (and patched) in 2021, the speed at which they were seized upon by attackers was such that Sophos expects to see continued attempts to mass-abuse IT administration tools and exploitable internet facing services by both sophisticated attackers and run-of-the-mill cybercriminals
· Sophos also expects cybercriminals to increase their abuse of adversary simulation tools, such as Cobalt Strike Beacons, mimikatz and PowerSploit. Defenders should check every alert relating to abused legitimate tools or combination of tools, just as they would check a malicious detection, as it could indicate the presence of an intruder in the network
· In 2021, Sophos researchers detailed a number of new threats targeting Linux systems and expect to see a growing interest in Linux-based systems during 2022, both in the cloud and on web and virtual servers
· Mobile threats and social engineering scams, including Flubot and Joker, are expected to continue and diversify to target both individuals and organizations
· The application of artificial intelligence to cybersecurity will continue and accelerate, as powerful machine learning models prove their worth in threat detection and alert prioritization. At the same time, however, adversaries are expected to make increasing use of AI, progressing over the next few years from AI-enabled disinformation campaigns and spoof social media profiles to watering-hole attack web content, phishing emails and more as advanced deepfake video and voice synthesis technologies become available
To learn more about the threat landscape in 2021 and what this means for IT security in 2022, read the full Sophos 2022 Threat Report.
Additional content for the Sophos 2022 Threat Report:
· Video of the headline findings, presented by Chester Wisniewski, principal research scientist, Sophos
· An article on SophosLabs Uncut recapping the report sections
· A Sophos News opinion piece by Wisniewski on the ransomware turf wars
· A Naked Security article introducing the report
Telecom
NCC Asks Telcos to Make Budgetary Provisions for Cybersecurity

Nigerian Communications Commission (NCC) has directed telecommunications operators to make dedicated budgetary provisions for cybersecurity as part of efforts to strengthen the resilience of Nigeria’s communications infrastructure against the growing wave of cyber threats.

The directive forms part of the Commission’s Cyber Resilience Framework for the Nigerian Communications Sector (CRF-NCS), which introduces new governance, risk management and operational requirements aimed at safeguarding the country’s critical telecommunications infrastructure from increasingly sophisticated cyberattacks.
Under the framework, all licensed telecom operators are expected to establish formal cybersecurity governance structures, dedicate adequate financial resources to cyber resilience programmes, and integrate cybersecurity into their enterprise-wide risk management processes.
The Commission said operators must ensure cybersecurity investments are no longer treated as optional operational expenses but as strategic business priorities necessary to protect network infrastructure, customer information and the country’s digital economy.
According to the NCC, licensees are expected to allocate sufficient budgets to support cyber risk assessments, security technologies, staff training, incident response capabilities, continuous monitoring and compliance with regulatory requirements.
The framework also requires operators to designate senior executives responsible for cybersecurity oversight.
At the same time, boards of directors are expected to provide strategic direction and ensure adequate funding for cyber resilience initiatives.
Speaking on the need for a stronger cybersecurity regime during the unveiling of the framework, Abraham Oshadami, executive commissioner, Technical Services, NCC, said, “Given the increasing digitalisation of services, the rapid growth of data exchange, and the sophisticated nature of modern cyber threats, the need for a robust, adaptive and inclusive cybersecurity framework has become more urgent.”
He added, “Both state and non-state actors are targeting essential sectors—including ours—through coordinated cyber and physical attacks. These attacks frequently target control systems and data integrity, underscoring the critical risks posed to operational technology (OT), especially in our sector.”
“As cyber threats evolve, they endanger not only system performance but also human safety, amplifying the severity and consequences of disruptions to vital communications infrastructure. Cybersecurity now encompasses human safety and must address the real risk to people’s lives when a system is attacked or compromised.”
The Commission further stated that operators are required to develop comprehensive cybersecurity implementation plans, conduct periodic risk assessments, establish business continuity and disaster recovery procedures, and regularly test their cyber defence capabilities.
In addition, the framework makes cyber incident reporting compulsory. Licensees must inform the NCC’s CSIRT of any major cybersecurity breach within four hours of discovery, and provide a thorough post-incident analysis after mitigation is complete.
Telecom
Glo Leads Internet Growth Figures in Nigeria for May

Digital solution provider, Globacom has recorded the highest Internet subscriber growth among Nigeria’s major telecom companies for the month of May.

Data from the Nigerian Communications Commission, NCC, Nigeria’s total Internet users increased to 157 million in May, up from 154.3 million in April. That is a growth of 2.67 million users in one month.
Globacom led the market by adding about 1.2 million new Internet subscribers. This means Glo was responsible for almost half of all new Internet users in May.
The company’s subscriber base grew from 15.5 million in April to 16.8 million in May. Airtel came second with 1.07 million new users, moving from 54.8 million to 55.8 million. MTN added 382,894 users to reach 83.5 million.
T2 Mobile, formerly 9mobile, recorded no growth for the second month in a row. Its subscriber base remained at 802,534. This is despite its roaming agreement with MTN, which was approved almost a year ago to help T2 customers use MTN’s network in areas with poor coverage.
Industry experts say Glo’s strong growth is due to its ongoing network upgrade. Since last year, the company has been building new base stations, expanding its fibre network, and adding thousands of new 4G sites across cities and rural areas.
The upgrades have improved voice and data quality for customers, while Globacom remain committed to providing better network experience and affordable Internet services to more Nigerians.
Telecom
MTN Paid 600Bn in Taxes in H1 2026 – Kadri, MTN CFO

MTN Nigeria’s half-year 2026 performance reflects more than revenue growth, highlighting the wider economic activity generated through tax payments, infrastructure investment and shareholder returns.

Kadri, MTN CFO
Beyond its financial results, the telecommunications operator said it continues to channel substantial resources into expanding network infrastructure, meeting statutory obligations and delivering value across its stakeholder ecosystem.
The company disclosed that it paid more than ₦600 billion in taxes, customs duties, regulatory levies and other statutory obligations over the past year.
It also invested over ₦1.6 trillion in capital expenditure since January 2025 to expand network capacity and improve service quality, while declaring an interim dividend of ₦26 per share for shareholders.
Speaking on Arise News’ Global Business Report, MTN Nigeria’s Chief Financial Officer, Modupe Kadri, explained that the company’s earnings are shared across several stakeholders before returns reach investors. “For every one naira of revenue, about 24 kobo becomes profit.
“The government receives over ₦600 billion through taxes and levies, operating costs account for a significant portion of our revenue, and every participant within the ecosystem benefits from the value we create,” he said.
According to the Nigerian Communications Commission (NCC), telecommunications remains one of the largest contributors to Nigeria’s Gross Domestic Product, supporting digital financial services, education, healthcare, commerce and public services. Continued investment by operators has also been identified as critical to expanding broadband access and improving digital inclusion across the country.
Kadri noted that shareholder returns remain an important part of MTN’s capital allocation strategy, but stressed that they represent only one aspect of the company’s broader economic contribution.
“Even when we declare dividends, the government still receives withholding tax, while we continue investing heavily in our network because sustaining quality service requires ongoing capital commitment,” he said.
E-Business3 days agoKaspersky Reveals a New Malicious Framework Targeting Cryptocurrency Users with the Use of OkoSpyware
E-Business3 days agoCMS T&M Launches TMO Rides to Enable a Faster & Cashless Transport Experience for CMS – Ajah Passengers
E-Business3 days agoFirm to recruit over 100 professionals to boost NRS e-Invoicing compliance
E-Business3 days agoNigeria Tightens Data Privacy Compliance as FG Issues Directive to MDAs
Telecom3 days agoFG Commences 90,000km Fibre Optic Rollout within Weeks
E-Financial2 days agoAccess Holdings Deepens Sustainable Finance Impact, Expanding Green Assets to ₦92.14 Billion
Telecom3 days agoDimension Data to Channel Funds to Support Nigerian Fibre Expansion
E-Financial3 days agoZenith Bank Confirms Cyberattack, Says Hackers Accessed Limited Customer Data




















