E-Business
Kaspersky Warns of Top IT Security Threats in Africa

Despite research showing an overall decrease in certain malware families and types in sub-Saharan Africa (SSA) in H1 2020 (36% decrease in South Africa, 26% decrease in Kenya and a 2.7% decrease in Nigeria), Kaspersky stresses that the human cyber threat remains rife, where Africa is not immune to the evolving techniques of Advanced Persistent Threats (APTs), as well as the possibilities of being a future target of hacking-for-hire threat actor groups.

Kaspersky research has found that globally, APT groups are evolving their techniques and are upgrading their toolset to continue stealing sensitive information.
Furthermore, Kaspersky has seen a rise of hackers-for-hire or cyber mercenaries during the first two quarters of 2020. In fact, three cyber mercenary groups have been exposed across the world this year alone.
As this activity has taken place outside of Africa, Kaspersky suspect that these types of actors may have been somewhat forgotten and do not necessarily form part of cyber defence strategies.
However, the region may become a focus of these groups in the coming months and thus, businesses and entities need to have an understanding of these emerging threats, along with the threat of APTs, to be prepared and take proactive steps towards effective cybersecurity.
Hackers-for-hire or cyber mercenaries do not necessarily have monetary motivations like traditional cybercrime. Instead, they steal private data to monetise it in a different way – usually for the purpose of providing advice or insights, based on the data, to share value of a competitive advantage.
For example, a bank might get targeted and have its data analysed to gain an understanding of its market exposure, clients, and back-end systems. A competitor can use that to gain significant benefit. The reality is that in this evolving cyberthreat landscape, no company or government institution can consider themselves safe.
In South Africa, Kenya and Nigeria, APT groups are exploiting the current uncertainty around COVID-19 to steal sensitive information. More sophisticated techniques have emerged that delivers malware in non-conventional ways.
While overall malware attacks in South Africa, Kenya and Nigeria decreased during the first two quarters of 2020, certain malware types, such as the STOP ransomware, are proving increasingly popular for certain cybercriminals.
The same applies to financial malware in South Africa and Nigeria as examples. So, even though it decreased in these countries, certain financial malware types are gaining in popularity thanks to their unique techniques which these groups are exploiting to monetise data. This emphasises that attacks are becoming more targeted and at specific companies, in specific regions and for specific purposes.
The top industries under attack in Sub-Saharan Africa in H1 2020 include government, education, healthcare, and military. While government and military present compelling – and obvious – targets, education and healthcare are often used as pivot points to gain access to other institutions. Sometimes, an entity is a victim while other times it is the target.
The top three threat actors in these regions in this regard are TransparentTribe, Oilrig, and MuddyWater.
Says Maher Yamout, Senior Security Research, Global Research & Analysis Team at Kaspersky; “The remainder of the year will likely see APT groups and hacking-for-hire threat actors increase in prominence across the globe.
Africa will continue to see more sophisticated APTs emerge and we also suspect that the hacking-for-hire actor type could target companies in Africa in the future. We also anticipate that cybercriminals will increase targeted ransomware deployment using different ways.
These can range from trojanised cracked software to exploitation across the supply chain of the targeted industry. Data breaches will certainly become more commonplace especially as people will continue to work remotely for the foreseeable future while exposing their systems to the Internet without adequate protection.”
While prevention is ideal, detection is a must. Realistically, no organisation or government department can prevent everything. But if there is an understanding of the technology environment and having the ability to detect any deviation from the baseline, decision-makers will go to great strides in mitigating the risk of compromise and by understanding the threat dynamics, organisations can better protect themselves from evolving cyberattacks.
E-Business
Firm Advocates Healthy IT Habits to Strengthen Cyber Resilience

At the recent Cyber Security Weekend 2026 conference, Kaspersky shared the findings from its survey titled “Cybersecurity in the workplace: Employee knowledge and behaviour” which was conducted among employees from the Middle East, Turkiye and Africa (META) region.

The study highlights that everyday IT habits, including decluttering computers and reducing digital fatigue, can have a direct and often underestimated impact on an organisation’s cyber resilience.
The Kaspersky survey points to a growing challenge of digital fatigue in the workplace. 13.5% of employees surveyed in the META region confirmed that they made IT-related mistakes due to a lack of cybersecurity knowledge – a figure that shows the critical importance of continuous cybersecurity training and awareness programmes.
Among other reasons behind IT mistakes, respondents cited being in a hurry (30%), oversight (14%), being tired or stressed (12.9%) and having too many notifications (10%). The constant barrage of alerts, messages, and on-screen clutter is becoming an acute problem that can lead to costly IT errors, overlooked social engineering attacks, and even to cyber breaches.
The survey also examined employees’ digital workspace habits. An overwhelming 44.5% of respondents in the META region reported having between 10 and 20 icons on their desktop, while 30% admitted to having even more – with half to a full screen covered in them.
Meanwhile, 33% of respondents also keep more than 10 tabs open in their browser at any given time. Excessive icons and open tabs do more than distract attention and fuel procrastination – they can slow device performance and, in the case of unused applications, quietly collect data.
Interestingly, most employees regularly disinfect their keyboards and phone surfaces (21.5% have adopted this habit since the COVID pandemic). However, digital cleanliness has not kept pace: 55% of respondents remove needless files once a month or more often; the rest perform digital clean-ups far less frequently – once a quarter, or even once a year.
Managing digital noise is key to staying alert: only essential notifications should remain active, especially during periods of deep focus on critical project deliverables. Regular breaks are just as vital for maintaining both well-being and cyber vigilance.
According to the survey, 78% of respondents spend their work breaks eating or drinking, while 58% chat with friends and colleagues. However, stretching and physical exercise is a more effective way to relieve stress and recharge focus – a habit adopted by only 14% of employees.
“It is important to recognise that digital fatigue is a real and growing stress factor: the constant stream of notifications, cluttered screens, and information overload gradually erode focus and make employees far more susceptible to mistakes and social engineering attacks. Simplifying your digital environment is not just a productivity tip, it is a cybersecurity measure”, says Brandon Muller, senior security consultant for the META region at Kaspersky.
E-Business
Extremist Groups Are Using Social Media to Recruit African Youth, New Report Warns

Pan-African digital rights organisation Paradigm Initiative (PIN) has warned that violent extremist groups are increasingly exploiting digital platforms to recruit, radicalise and manipulate young people across the Sahel region.

The organisation raised the concern in a new policy brief titled “Digital Frontlines: Countering Online Radicalisation and Violent Extremist Narratives in the Sahel.”
According to the publication, extremist groups are shifting from traditional recruitment methods to digital platforms, including social media, encrypted messaging applications, short-form video platforms and online financial incentives, to target vulnerable populations.
PIN noted that unemployed youths and people facing insecurity and limited economic opportunities are particularly susceptible to online recruitment campaigns.
The organisation said that although governments have intensified efforts to combat violent extremism, responses to the digital dimension of the threat have failed to keep pace with rapidly evolving online tactics.
It argued that addressing online radicalisation requires more than surveillance and restrictive measures, recommending investments in digital literacy, stronger community resilience, improved early-warning systems and credible counter-narratives.
PIN also urged governments to work closely with technology companies and civil society organisations to disrupt extremist recruitment while protecting citizens’ digital rights.
The report further highlighted the growing convergence between organised crime and violent extremist groups, noting that online propaganda increasingly promises financial rewards, belonging and purpose to vulnerable young people.
According to the organisation, this trend underscores the need for policymakers to prioritise prevention alongside conventional security responses.
Speaking on the findings, Moussa Waly SENE, Programmes Officer for Francophone Africa at Paradigm Initiative, described the digital space as a new frontline in the fight against violent extremism.
“As more young Africans come online, stakeholders must ensure that digital platforms remain spaces for opportunity, innovation and civic participation, not recruitment grounds for violent extremist groups. Protecting digital rights and protecting vulnerable communities should be mutually reinforcing objectives,” he said.
Among its recommendations, the policy brief called for stronger regional cooperation to tackle cross-border online extremist networks, rights-respecting content moderation and greater accountability by digital platforms.
It also advocated expanded digital literacy programmes to strengthen resilience against online manipulation and community-led initiatives that empower young people to identify and reject extremist narratives.
The organisation further urged policymakers to develop security measures that balance national security objectives with the protection of privacy, freedom of expression and access to information.
E-Business
Kaspersky Reveals a New Malicious Framework Targeting Cryptocurrency Users with the Use of OkoSpyware

At its recent annual Cyber Security Weekend for the Middle East, Turkiye and Africa (META) region, Kaspersky Global Research and Analysis Team (GReAT) shared insights about the new OkoBot campaign targeting cryptocurrency users.

The new sophisticated framework employs TookPS to exfiltrate seed phrases and uses a new OkoSpyware module to monitor Chromium-based browsers and deploy various malware strains, including the Rilide stealer.
It has already targeted hundreds of victims across over 25 countries, with the highest number of affected end users recorded in Brazil, Vietnam, Canada, Mexico and Turkiye. According to Kaspersky experts, the threat remains active and primarily poses a risk to cryptocurrency users.
In January 2026, experts from the Kaspersky Global Research and Analysis Team (GReAT) identified multiple attacks involving a previously unknown malware capable of capturing the contents of cryptocurrency wallet windows. Dubbed Okobot, the new sophisticated malware framework comprises more than 20 malicious payloads and implants designed to perform a wide range of functions, including collecting local files, executing remote commands, downloading arbitrary browser extensions, stealing cryptocurrency wallets, harvesting seed phrases and credentials, recording video and carrying out other malicious activities.
One of the new implants used in the campaign is a loader that modifies browser memory to load and hide malicious extensions. OkoBot also includes a new OkoSpyware module, which captures keystrokes and the video stream of a target application’s window.
Currently available information does not allow the campaign to be attributed to any known crimeware actor with high confidence. However, the techniques and infostealer involved are widely used by Russian-speaking threat actors, and technical analysis has also revealed code artifacts in Russian.
The initial infection typically occurs through two main vectors: ClickFix attacks, in which threat actors use social engineering to trick users into running malicious code, and malware distributed via GitHub under the guise of legitimate software. During the investigation, researchers identified one such case involving a fake installer for SQL Server Management Studio (SSMS), a widely used Microsoft database management tool.
The malicious framework includes SeedHunter, a malware component that monitors active system processes and injects an implant into Trezor Suite, Ledger Wallet, and Ledger Live, – official applications used to manage cryptocurrency assets. When it detects a connected Trezor or Ledger hardware wallet, it triggers the hooked functions to display a hard-coded phishing page aimed at stealing the user’s seed phrase, using a distinct layout for each wallet type.
“The OkoBot campaign has been active for more than a year and remained ongoing as of July 2026. The observed infection vectors strongly suggest that developers are among its primary targets. Of particular concern is the malware’s continued evolution, which indicates that the framework is being actively maintained. As distribution efforts persist, the campaign has the potential to reach more users and expand into additional countries in the near term,” says Dmitry Galov, Head of the Russia and CIS unit at Kaspersky Global Research and Analysis Team.
E-Business3 days agoKaspersky Reveals a New Malicious Framework Targeting Cryptocurrency Users with the Use of OkoSpyware
E-Business3 days agoCMS T&M Launches TMO Rides to Enable a Faster & Cashless Transport Experience for CMS – Ajah Passengers
E-Business3 days agoFirm to recruit over 100 professionals to boost NRS e-Invoicing compliance
E-Business3 days agoNigeria Tightens Data Privacy Compliance as FG Issues Directive to MDAs
Telecom3 days agoFG Commences 90,000km Fibre Optic Rollout within Weeks
E-Financial2 days agoAccess Holdings Deepens Sustainable Finance Impact, Expanding Green Assets to ₦92.14 Billion
Telecom3 days agoDimension Data to Channel Funds to Support Nigerian Fibre Expansion
E-Financial3 days agoZenith Bank Confirms Cyberattack, Says Hackers Accessed Limited Customer Data




















