Connect with us

E-Business

SophosLabs Research Reveals Africa’s Cyber Threats Level

Published

on

sophos new.jpg
Kindly share this post

Sophos, a global leader in network and endpoint security (www.sophos.com/en-us/lp/endpoint5reasons.aspx?cmp=701j0000001q1B9AAI), has revealed SophosLabs research that indicates a growing trend among cybercriminals to target and even filter out specific countries when designing ransomware and other malicious cyberattacks.

From the research result, African countries where shown to be on average threat level.

The African countries that were at an average level, according to SophosLabs include: Tanzania – 11.1 percent Kenya – 11.5 percent South Africa – 11.6 percent Egypt – 12.4 percent Angola – 15.7 percent Nigeria – 15.7 percent Tunisia – 16.4 percent Morocco – 16.6 percent Uganda – 24.9 percent Ghana – 25.5 percent Mozambique – 28.3 percent Algeria – 30.7 percent Zambia – 35.5 percent and Malawi – 39.4 percent.

The research includes information from millions of endpoints worldwide and is analyzed by the team at SophosLabs.

To lure more victims with their attacks, cybercriminals are now crafting customized spam to carry threats using regional vernacular, brands and payment methods for better cultural compatibility, according to Sophos.

Advertisement

Ransomware cleverly disguised as authentic email notifications, complete with counterfeit local logos, is more believable, highly clickable and therefore more financially rewarding to the criminal.

To be as effective as possible, these scam emails now impersonate local postal companies, tax and law enforcement agencies and utility firms, including phony shipping notices, refunds, speeding tickets and electricity bills.

SophosLabs has seen a rise in spam where the grammar is more often properly written and perfectly punctuated.

“You have to look harder to spot fake emails from real ones,” said Chester Wisniewski, senior security advisor at Sophos. “Being aware of the tactics used in your region is becoming an important aspect of security.”

Researchers also saw historic trends of different ransomware strains that targeted specific locations. Versions of CryptoWall predominantly hit victims in the U.S., U.K., Canada, Australia, Germany and France, TorrentLocker attacked primarily the U.K., Italy, Australia and Spain and TeslaCrypt honed in on the U.K., U.S., Canada, Singapore and Thailand.

Advertisement

The analysis also shows Threat Exposure Rates (TER) for countries during the first three months of 2016.

Although Western economies are more highly targeted, they typically have a lower TER. Nations ranked with the lowest TER include France at 5.2 percent, Canada at 4.6 percent, Australia at 4.1 percent, the U.S. at 3 percent, and the U.K. at 2.8 percent..

The African countries were reported to be at an average level.

Algeria at 30.7 percent, Bolivia at 20.3 percent, Pakistan at 19.9 percent, China at 18.5 percent and India at 16.9 percent are among countries with the highest percentage of endpoints exposed to a malware attack

“Even money laundering is localized to be more lucrative. Credit card processing can be risky for criminals, so they started using anonymous Internet payment methods to extort money from ransomware victims,” said Wisniewski. “We have seen cybercrooks using local online cash-equivalent cards and purchasing locations, such as prepaid Green Dot MoneyPak cards from Walgreens in the U.S. and Ukash, which is now paysafecard, from various retail outlets in the U.K.”

Advertisement

Tweet This: “Designer” cyber threats on the rise with localized logos, language and payment methods, according to Sophos.

The concept of filtering out specific countries has also emerged as a trend.

“Cybercriminals are programming attacks to avoid certain countries or keyboards with a particular language,” said Wisniewski. “This could be happening for many reasons. Maybe the crooks don’t want attacks anywhere near their launch point to better avoid detection. It could be national pride or perhaps there’s a conspiratorial undertone to create suspicion about a country by omitting it from an attack.”

Banking is an example of how cybercriminals are using location-based malware to be more prosperous. Sophos research reveals historically how Trojans and malware used to infiltrate banks and financial institutions converges on specific regions: Brazilian banker Trojans and variants pinpoint Brazil; Dridex is predominant in the U.S. and Germany; Trustezeb is most prevalent in German speaking counties; Yebot is popular in Hong Kong and Japan.

Zbot is wider spread, but mostly in the U.S., U.K., Canada, Germany, Australia, Italy, Spain and Japan.

Advertisement

“There is an entire cottage industry of uniquely-crafted Trojans just targeting banks in Brazil,” said Wisniewski.

With cybercriminals having a deliberate hand in creating threats that look authentic and are specifically targeted, it is more difficult to recognize malicious spam.

Home computer users are often a target of these attacks and should protect their systems from sophisticated malware threats. Free enterprise-grade security software that can detect threats and protect both Mac and PC for the home user is available from Sophos Home.

This research and analysis is from SophosLabs, a network of security experts across the world who detect and track all types of Internet breaches 24/7/365 worldwide, including computer viruses, advanced malware and Trojans, spam, web threats, hack attacks and more.

SophosLabs receives and investigates millions of emails, URLs, files and other data points daily and leverages its extensive expertise within the group to develop new definitions that detect entire classes of threats and new variants.

Advertisement

With facilities strategically located in Australia, Hungary, U.K. and Canada, SophosLabs experts also monitor and determine threat trends and maintain malware, spam and web threat dashboards in real time.

More than 100 million users in 150 countries rely on Sophos’ complete security solutions as the best protection against complex threats and data loss.

Simple to deploy, manage, and use, Sophos’ award-winning encryption, endpoint security, web, email, mobile and network security solutions are backed by SophosLabs – a global network of threat intelligence centers.

Sophos is headquartered in Oxford, U.K., and is publicly traded on the London Stock Exchange under the symbol “SOPH.” More information is available at www.sophos.com.

*Sample of a Phishing mail intercepted by Nigeria CommunicationsWeek reporter on Monday, May 9, 2016. Google has since denied been the source of such email.

Advertisement

 

 

Kindly share this post

Nigeria CommunicationsWeek believes that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. So since 2007, we have devoted our energy to independent reportage of technology and how they affect lives.

Continue Reading
Advertisement
Comments

E-Business

Kaspersky Reveals a New Malicious Framework Targeting Cryptocurrency Users with the Use of OkoSpyware

Published

on

Kindly share this post

At its recent annual Cyber Security Weekend for the Middle East, Turkiye and Africa (META) region, Kaspersky Global Research and Analysis Team (GReAT) shared insights about the new OkoBot campaign targeting cryptocurrency users.

The new sophisticated framework employs TookPS to exfiltrate seed phrases and uses a new OkoSpyware module to monitor Chromium-based browsers and deploy various malware strains, including the Rilide stealer.

It has already targeted hundreds of victims across over 25 countries, with the highest number of affected end users recorded in Brazil, Vietnam, Canada, Mexico and Turkiye. According to Kaspersky experts, the threat remains active and primarily poses a risk to cryptocurrency users.

In January 2026, experts from the Kaspersky Global Research and Analysis Team (GReAT)  identified multiple attacks involving a previously unknown malware capable of capturing the contents of cryptocurrency wallet windows. Dubbed Okobot, the new sophisticated malware framework comprises more than 20 malicious payloads and implants designed to perform a wide range of functions, including collecting local files, executing remote commands, downloading arbitrary browser extensions, stealing cryptocurrency wallets, harvesting seed phrases and credentials, recording video and carrying out other malicious activities.

One of the new implants used in the campaign is a loader that modifies browser memory to load and hide malicious extensions. OkoBot also includes a new OkoSpyware module, which captures keystrokes and the video stream of a target application’s window.

Advertisement

Currently available information does not allow the campaign to be attributed to any known crimeware actor with high confidence. However, the techniques and infostealer involved are widely used by Russian-speaking threat actors, and technical analysis has also revealed code artifacts in Russian.

The initial infection typically occurs through two main vectors: ClickFix attacks, in which threat actors use social engineering to trick users into running malicious code, and malware distributed via GitHub under the guise of legitimate software. During the investigation, researchers identified one such case involving a fake installer for SQL Server Management Studio (SSMS), a widely used Microsoft database management tool.

The malicious framework includes SeedHunter, a malware component that monitors active system processes and injects an implant into Trezor Suite, Ledger Wallet, and Ledger Live, – official applications used to manage cryptocurrency assets. When it detects a connected Trezor or Ledger hardware wallet, it triggers the hooked functions to display a hard-coded phishing page aimed at stealing the user’s seed phrase, using a distinct layout for each wallet type.

“The OkoBot campaign has been active for more than a year and remained ongoing as of July 2026. The observed infection vectors strongly suggest that developers are among its primary targets. Of particular concern is the malware’s continued evolution, which indicates that the framework is being actively maintained. As distribution efforts persist, the campaign has the potential to reach more users and expand into additional countries in the near term,” says Dmitry Galov, Head of the Russia and CIS unit at Kaspersky Global Research and Analysis Team.

Advertisement

Kindly share this post
Continue Reading

E-Business

PalmPay Targets Hong Kong IPO after $1Bn Valuation

Published

on

Kindly share this post

PalmPay, one of Africa’s leading digital financial services companies, is considering a listing on the Hong Kong Stock Exchange after attaining a valuation of more than one billion dollars, according to a Bloomberg report.

PalmPay Targets Hong Kong IPO After $1bn Valuation, Eyes Fresh Capital Raise

PalmPay

The report, citing sources familiar with the matter, said the fintech company was also seeking to raise between 150 million dollars and 200 million dollars in fresh funding ahead of a potential Initial Public Offering (IPO).

According to the sources, the additional capital is expected to support PalmPay’s next phase of expansion across Africa and selected Asian markets.

If completed, the IPO would rank among the most significant public market debuts by an African fintech company and could encourage other technology firms on the continent to explore listings beyond the traditional financial centres of London and New York.

Founded in 2019, PalmPay has emerged as one of Africa’s fastest-growing consumer fintech platforms, providing digital payments, money transfers, savings, lending and merchant payment solutions.

The company has established its strongest market presence in Nigeria while expanding operations into Ghana, Tanzania and Bangladesh as part of its international growth strategy.

Advertisement

PalmPay says it currently serves more than 35 million registered users and supports over one million businesses and merchants, processing millions of transactions daily.

Its rapid growth has positioned it among Africa’s leading fintech firms, alongside companies such as Flutterwave, Moniepoint, OPay, Wave and Onafriq.

Unlike many technology startups that have prioritised rapid customer acquisition over profitability, PalmPay reportedly achieved profitability in 2025, a development analysts say could enhance investor confidence as the company prepares for another fundraising round and an eventual stock market listing.

The report noted that Hong Kong could offer strategic advantages for PalmPay due to its strong commercial ties with Asian investors and the company’s growing presence in emerging Asian markets.

PalmPay’s early investors include Transsion Holdings, the maker of the Tecno, Infinix and itel smartphone brands, as well as investors linked to NetEase and MediaTek.

Advertisement

Industry analysts believe these long-standing relationships could make Hong Kong a natural destination for PalmPay’s public listing while broadening access to investors already familiar with its business model.

The company’s IPO plans come as venture capital investment in African startups has slowed considerably since the record funding years of 2021 and 2022, prompting many technology firms to focus on profitability, stronger balance sheets and sustainable long-term growth.

Against that backdrop, PalmPay’s proposed fundraising and listing are expected to serve as an important test of international investor appetite for profitable African fintech companies.

The company’s valuation also underscores the resilience of Africa’s digital payments sector, driven by rising smartphone adoption, expanding internet access and increasing demand for cashless transactions across the continent.

Although PalmPay has yet to make a final decision on either the fundraising or the IPO timetable, the reported preparations indicate that the company is positioning itself for its next phase of growth.

Advertisement

Industry observers say a successful Hong Kong listing could provide fresh momentum for Africa’s technology sector and create an alternative pathway for high-growth startups seeking access to global capital markets.

Kindly share this post
Continue Reading

E-Business

CMS T&M Launches TMO Rides to Enable a Faster & Cashless Transport Experience for CMS – Ajah Passengers

Published

on

Kindly share this post

CMS Transport Management (CMS T&M), one of Lagos’ longest-standing and most trusted transport operators, officially launches a new service known as TMO Rides.

CMS T&M Launches TMO Rides to Enable a Faster & Cashless Transport Experience for CMS – Ajah Passengers

This new initiative is designed to simplify the daily commute by introducing seamless cashless payments for passengers across its bus network.

For over 58 years, CMS T&M has played a significant role in moving millions of passengers daily along the CMS – Ajah routes through its fleet of high-capacity buses popularly.

The launch of TMO Rides marks another milestone in the company’s journey toward building a smarter, more efficient transport experience.

Through the initiative, passengers will have access to TMO Cards for a seamless transport. This is more exciting because TMO launches with 2 consecutive apps.

Advertisement

These apps help to eliminate the need for cash transactions while reducing boarding delays and create a more convenient experience for passengers.

Beyond introducing digital fare payments, the initiative reflects CMS T&M’s broader commitment to modernize public transportation through innovation, operational efficiency and improved customer experience.

CMS T&M operates within Nigeria’s regulated transport ecosystem as a registered member of the BRT Association of Nigeria (BRTAN), where it is also an equity stakeholder, reinforcing its commitment to a cooperative-driven transport system.

The company is equally registered with the Lagos Metropolitan Area Transport Authority (LAMATA), the agency responsible for planning, regulating and franchising public transportation in Lagos State, and is also a member of the National Union of Road Transport Workers (NURTW) that promotes safe and organized road transport operations.

Speaking on the launch, Andy, Managing Director of CMS T&M, said: “For nearly six decades, our focus has remained the same, which is moving people safely and efficiently.

Advertisement

“As the transportation needs of Lagos continue to evolve, we must evolve with them. TMOx Rider is about making everyday commuting easier by giving our passengers a faster, more convenient way to pay while improving the overall travel experience.

“This launch represents another important step in our commitment to building a smarter, more accessible transport system for everyone.”

The launch of TMO Rides forms part of CMS T&M’s long-term vision of embracing technology to improve public transportation without compromising the trust and consistency the passengers have relied on for generations.

The cashless payment infrastructure empowering TMO Rides is enabled by Treepz, whose mobility technology supports digital fare collection and operational efficiency.

By providing the technology behind the initiative, Treepz is helping CMS T&M expand access to modern, seamless transportation while advancing a shared vision of making everyday mobility more connected, convenient and accessible across Lagos.

Advertisement

Visit our website: https://www.cmstaxiandmotor.com/

Kindly share this post
Continue Reading

Trending