E-Business
Kaspersky’s Projections for 2024’s Advanced Threats Landscape

Kaspersky Global Research and Analysis Team (GReAT) experts offer insights and projections for 2024 in the Kaspersky Security Bulletin, with a focus on the evolution of Advanced Persistent Threats (APT).

Kaspersky researchers predict APT actors will introduce new exploits on mobile, wearables, and smart devices and use them to form botnets, refine supply chain attack methods, and utilise AI for more effective spear-phishing. These advancements are anticipated to intensify politically motivated attacks and cybercrime.
AI-powered impersonation, the rise of creative exploits for mobile, and new botnets
Emerging AI tools will streamline spear-phishing message production, even enabling the mimicry of specific individuals. Attackers may devise creative automation methods by gathering online data and feeding it to LLMs to craft letters in the style of a person connected to the victim.
“Operation Triangulation” marks a groundbreaking year for mobile exploits, potentially inspiring more research into APTs attacking mobile, wearables, and smart devices. We will likely witness threat actors broadening their surveillance efforts, targeting various consumer devices through vulnerabilities and “silent” exploit delivery methods, including zero-click attacks through messengers, one-click attacks via SMS or messaging apps, and network traffic interception. Protection of personal and corporate devices has become increasingly vital.
The exploitation of vulnerabilities in commonly used software and appliances is yet another point where we should be vigilant. The discovery of high and critical severity vulnerabilities sometimes receives limited research and delayed fixes, potentially paving the way for new, large-scale, and stealthy botnets capable of targeted attacks.
Growth in cyberattacks by state-sponsored actors and hacktivism as a new normal
State-sponsored cyberattack numbers also have the potential to surge in the year ahead, amid increasing geopolitical tensions. These attacks will likely threaten data theft or encryption, IT infrastructure destruction, long-term espionage, and cyber-sabotage.
Another notable trend is hacktivism, which has become more common as part of geopolitical conflicts. Geopolitical tensions indicate a likely increase in hacktivist activity, both destructive and aimed at spreading false information, leading to unnecessary investigations and subsequent alert fatigue of SOC analysts and cybersecurity researchers.
Other advanced threat predictions for 2024 include:
- Supply chain attacks as a service: operators’ bulk-buying access
Supply chain attacks targeting smaller firms to breach major ones: the Okta breaches in 2022-2023 highlight the threat’s scale. Motives of such attacks may range from financial gain to espionage. 2024 might witness new developments in dark web access market activities related to supply chains, enabling more efficient and large-scale attacks.
- Emergence of more groups offering hack-for-hire services
Hack-for-hire groups are on the rise, providing data theft services to clients ranging from private investigators to business rivals. This trend is expected to grow in the coming year.
- Kernel rootkits are hot again
Despite modern security measures like Kernel Mode Code Signing, PatchGuard, HVCI (Hypervisor-Protected Code Integrity), kernel-level code execution barriers are being bypassed by APTs and cybercrime groups. Windows kernel attacks are on the rise, enabled by WHCP abuses, and the underground market for EV certificates and stolen code signing certificates is growing. Threat actors are increasingly leveraging BYOVD (Bring Your Own Vulnerable Driver) in their tactics.
- Managed File Transfer (MFT) systems used for advanced attacks
Managed File Transfer (MFT) systems face escalating cyber threats, exemplified by 2023 breaches of MOVEit and GoAnywhere. This trend is poised to escalate, with cyber adversaries eyeing financial gains and operational disruptions.
The intricate MFT architecture, integrated into broader networks, harbors security weaknesses. Organisations should implement robust cybersecurity measures, including Data Loss Prevention and encryption, and foster cybersecurity awareness to fortify MFT systems against evolving threats.
“In 2023, the notable surge in the availability of AI tools didn’t elude the attention of advanced malicious actors engaged in extensive and highly sophisticated campaigns.
“However, we anticipate that upcoming trends go beyond AI implications, including new methods for conducting supply chain attacks, the emergence of hack-for-hire services, novel exploits for consumer devices, and more.
“Our goal is to provide defenders with advanced threat intelligence that stays ahead of the latest threat developments, enhancing their capacity to fend off cyberattacks more effectively”, says Igor Kuznetsov, Director, Global Research and Analysis Team (GReAT) at Kaspersky.
E-Business
HURIWA, CLO Protests Bill Asking Social Media Firms’ to Open Shops Nigeria

Human Rights Writers Association of Nigeria (HURIWA) has opposed a bill seeking to compel major global social media companies to establish physical offices in Nigeria.

The rights advocacy group urged the National Assembly to discard the proposed legislation, warning that it could become a tool for censorship and undermine citizens’ constitutional right to freedom of expression, despite being presented as a measure to strengthen Nigeria’s digital economy and improve corporate accountability.
The position was contained in a presentation submitted yesterday by Emmanuel Onwubiko, national coordinator, HURIWA, to the chairman of the Senate Committee on ICT and Cyber Security.
The bill, sponsored by Senator Ned Munir Nwoko, has already passed second reading in the Senate and is before the committee for further legislative consideration.
HURIWA said it carefully reviewed the proposed legislation and concluded that compelling global technology companies to establish offices in Nigeria was unnecessary and potentially counterproductive.
The organisation argued that while the firms generate substantial revenue from Nigeria’s vast digital market, they already engage Nigerians through existing structures, including paying eligible content creators, working with local technology professionals and participating in legal proceedings whenever required.
According to the group, appointing local representatives where necessary would adequately address concerns about engagement with regulators and users without forcing the companies to maintain physical offices.
It also dismissed claims that mandatory country offices would significantly improve consumer complaint resolution, technology transfer or employment generation.
HURIWA maintained that the platforms already have effective feedback mechanisms for resolving users’ complaints and routinely appear before Nigerian courts through their representatives whenever litigation arises.
The group, however, said its greatest concern was the potential for the proposed law to be used as an instrument for restricting freedom of expression.
It argued that establishing local offices could expose global social media companies to pressure from government authorities to remove online content considered critical of those in power.
According to the rights group, the presence of social media companies in Nigeria could become an avenue for authorities to pressure them into abandoning internationally recognised digital rights standards in favour of politically motivated content moderation.
It recalled previous attempts to regulate social media in Nigeria that generated widespread concerns over possible restrictions on free speech, stressing that any legislation affecting the digital space must contain clear safeguards against abuse.
The organisation warned that the proposed law should never become “a backdoor mechanism for government surveillance, arbitrary content removal or political censorship.
E-Business
Nigeria Leads Africa in Online Gambling Regulation – GCI

Nigeria has emerged as one of Africa’s most regulated online gambling markets, even as illegal operators continue to dominate the continent, according to a new report by Gaming Compliance International (GCI).

The report, the first comprehensive assessment of online gambling across all 54 African countries, showed that Africa’s online gambling Gross Gaming Revenue (GGR) reached $23 billion in 2025.
However, only $5.2 billion (23 per cent) was generated by licensed operators, while $17.8 billion (77 per cent) remained in the unregulated market.
In West Africa, total online gambling revenue rose to $4.8 billion in 2025 from $4.3 billion in 2024. Of the 2025 figure, regulated operators accounted for $1.5 billion (31 per cent), while $3.3 billion (69 per cent) flowed to unlicensed platforms, highlighting the region’s persistent enforcement challenges.
Nigeria stood out as the region’s strongest performer, recording the lowest unregulated market share at 56 per cent, compared with the West African average of 69 per cent and the African average of 77 per cent.
The study also found that online gambling participation across Africa increased from 198 million people (13 per cent of the population) in 2024 to 215 million (14 per cent) in 2025.
Despite this growth, GCI estimated that illegal operators deprived African governments of about $3.55 billion in tax revenue in 2025. The number of unlicensed gambling platforms targeting African consumers also rose to 4,129, up from 3,644 in 2024.
Commenting on the findings, Matt Holt, chief executive officer, GCI, said the report provides regulators with the first continent-wide benchmark for strengthening oversight and consumer protection.
Ismail Vali, president, GCI, urged governments to develop competitive and well-regulated markets that encourage consumers to patronise licensed operators, boost public revenue and attract greater investment.
Online gambling in Nigeria is regulated by the Nation Lottery Regulatory Commission.
E-Business
Kaspersky Warns Mobile‑data Buyers about Scammers Posing as Telecoms Operators

At the height of the Northern Hemisphere tourist season, demand for communications and mobile Internet services rises sharply. Kaspersky’s security experts have uncovered scams that target anyone purchasing mobile connections or SIM cards worldwide.

Fraudsters create counterfeit websites that look like the portals of major regional and international telecom providers to trick users into revealing their phone numbers, personal details or banking information.
Kaspersky is sharing several examples of these fake login pages that mimic legitimate telecom operator sites and giving recommendations on how not to be deceived.
In the first case, scammers exploit the brand name of an international telecommunications company operating services in Asia, Africa and Europe. Fake authentication pages encourage users to put in their phone number and credentials.
While the first example shows the different design, the second scam site closely mimics the original log in page, making it hard for users to tell the difference and spot a fake. Entering authentication or payment data on fraudulent web sites may result in money or data loss and become a reason for more frequent spam and fraudulent calls.
Another example is a scam page which poses as another international communications company, working in North Africa, the Middle East and Southeast Asia. In this scheme scammers encourage users to top up their mobile data/Internet plans by entering their personal information and bank cards details.
Kaspersky experts have also identified a scam when cyber criminals suggest users enter their personal data to check and pay a bill inquiry. Such scam schemes are usually aimed at gaining victims’ personal data for further fraud or account hacking and stealing money.
“Because of the active use of AI, scammers can now create fake pages with ever increasing accuracy and speed, targeting the most popular user interest areas. We constantly see scams revolving around sports events, music concerts, seasonal sales and holidays. Unfortunately, the telecoms industry is no exception.
To keep your data and money safe, be vigilant when purchasing mobile or Internet plans online. Using an eSIM – purchased through an official app – is one way to avoid fake telecom sites, as it eliminates the need to enter personal details on questionable web pages.
If you’re unsure about a site’s legitimacy, search for the brand name directly in a search engine and enable a security solution that blocks phishing links for you,” comments Tatyana Kulikova, cybersecurity expert at Kaspersky.
E-Business2 days agoKaspersky Warns Mobile‑data Buyers about Scammers Posing as Telecoms Operators
General News2 days agoThree Entrepreneurs Secure ₦5 Million at The Gathering on 100 Pitchathon
E-Financial2 days agoChatPay Unveils Public Waitlist for WhatsApp-Based Banking Platform
News2 days agoAfrican Judges Pledge Support for AfCFTA’s Success
Telecom2 days agoGSMA Says High Smartphone Costs Threatens Africa’s AI Future
Telecom2 days agoAirtel Africa Backs London Listing
E-Business2 days agoNigeria Leads Africa in Online Gambling Regulation – GCI
General News2 days agoCBN Has Not Published Annual Financial Statements Since 2022 despite Legal Requirement
















