E-Business
WannaCry: Kaspersky Records Over 45,000 Attacks in One Day

Barely a week ago, the world, saw the beginning of the Trojan encryptor WannaCry outbreak. It appears to be pandemic — a global epidemic.
“We counted more than 45,000 cases of the attack in just one day, but the true number is much higher,” Kaspersky writes in a blog post.
Recall several large organizations reported an infection simultaneously. Among them were several British hospitals that had to suspend their operations. According to data released by third parties, Kaspersky said that WannaCry has infected more than 200,000 computers. The sheer number of infections is a big part of the reason it has drawn so much attention.
The largest number of attacks occurred in Russia, but Ukraine, India, and Taiwan have suffered much damage from WannaCry as well. In just the first day of the attack, we found WannaCry in 74 countries.
The creators of WannaCry have taken advantage of the Windows exploit known as EternalBlue, which relies on a vulnerability that Microsoft patched in security update MS17-010, dated March 14 of this year. By using the exploit, the malefactors could gain remote access to computers and install the encryptor.
Generally, WannaCry comes in two parts. First, it’s an exploit whose purposes are infection and propagation. The second part is an encryptor that is downloaded to a computer after it has been infected.
“The first part is the main difference between WannaCry and the majority of encryptors. To infect a computer with a common encryptor, a user has to make a mistake, for example by clicking a suspicious link, allowing Word to run a malicious macro, or downloading a suspicious attachment from an e-mail message. A system can be infected with WannaCry without the user doing anything.
“If you have the update installed, then this vulnerability no longer exists for you, and attempts to hack the computer remotely through the vulnerability will fail. However, researchers from Kaspersky Lab’s GReAT (Global Research & Analysis Team) would like to emphasize that patching the vulnerability will not deter the encryptor entirely. Therefore, if you launch it somehow (see the above on making a mistake), then that patch will do you no good.
“After hacking a computer successfully, WannaCry attempts to spread itself over the local network onto other computers, in the manner of a computer worm. The encryptor scans other computers for the same vulnerability that can be exploited with the help of EternalBlue, and when WannaCry finds a vulnerable machine, it attacks the machine and encrypts files on it.
“Therefore, by infecting one computer, WannaCry can infect an entire local area network and encrypt all of the computers on the network. That’s why large companies suffered the most from the WannaCry attack — the more computers on the network, the greater the damage.
WannaCry
“As an encryptor, WannaCry (sometimes called WCrypt or, for no discernable reason, WannaCry Decryptor) behaves like any other encryptor; it encrypts files on a computer and demands ransom to decrypt them. It most closely resembles a variation of the infamous CryptXXX Trojan.
“WannaCry encrypts files of various types (the full list is here) including office documents, pictures, videos, archives, and other file formats that potentially contain critical user data. The extensions of the encrypted files are renamed .WCRY, and the files become completely inaccessible.
“After this, the Trojan changes the desktop wallpaper to a picture that contains information about the infection and actions that the user supposedly has to perform to recover the files. WannaCry spreads notifications as text files with the same information across folders on the computer to ensure that the user receives the message.
“As usual, the actions entail transferring a certain amount of money, in bitcoins, to the wallet of the perpetrators. After that, they say, they will decrypt all of the files. Initially, cybercriminals demanded $300 but then raised the stakes to $600”, the blog post reads.
E-Business
Extremist Groups Are Using Social Media to Recruit African Youth, New Report Warns

Pan-African digital rights organisation Paradigm Initiative (PIN) has warned that violent extremist groups are increasingly exploiting digital platforms to recruit, radicalise and manipulate young people across the Sahel region.

The organisation raised the concern in a new policy brief titled “Digital Frontlines: Countering Online Radicalisation and Violent Extremist Narratives in the Sahel.”
According to the publication, extremist groups are shifting from traditional recruitment methods to digital platforms, including social media, encrypted messaging applications, short-form video platforms and online financial incentives, to target vulnerable populations.
PIN noted that unemployed youths and people facing insecurity and limited economic opportunities are particularly susceptible to online recruitment campaigns.
The organisation said that although governments have intensified efforts to combat violent extremism, responses to the digital dimension of the threat have failed to keep pace with rapidly evolving online tactics.
It argued that addressing online radicalisation requires more than surveillance and restrictive measures, recommending investments in digital literacy, stronger community resilience, improved early-warning systems and credible counter-narratives.
PIN also urged governments to work closely with technology companies and civil society organisations to disrupt extremist recruitment while protecting citizens’ digital rights.
The report further highlighted the growing convergence between organised crime and violent extremist groups, noting that online propaganda increasingly promises financial rewards, belonging and purpose to vulnerable young people.
According to the organisation, this trend underscores the need for policymakers to prioritise prevention alongside conventional security responses.
Speaking on the findings, Moussa Waly SENE, Programmes Officer for Francophone Africa at Paradigm Initiative, described the digital space as a new frontline in the fight against violent extremism.
“As more young Africans come online, stakeholders must ensure that digital platforms remain spaces for opportunity, innovation and civic participation, not recruitment grounds for violent extremist groups. Protecting digital rights and protecting vulnerable communities should be mutually reinforcing objectives,” he said.
Among its recommendations, the policy brief called for stronger regional cooperation to tackle cross-border online extremist networks, rights-respecting content moderation and greater accountability by digital platforms.
It also advocated expanded digital literacy programmes to strengthen resilience against online manipulation and community-led initiatives that empower young people to identify and reject extremist narratives.
The organisation further urged policymakers to develop security measures that balance national security objectives with the protection of privacy, freedom of expression and access to information.
E-Business
Kaspersky Reveals a New Malicious Framework Targeting Cryptocurrency Users with the Use of OkoSpyware

At its recent annual Cyber Security Weekend for the Middle East, Turkiye and Africa (META) region, Kaspersky Global Research and Analysis Team (GReAT) shared insights about the new OkoBot campaign targeting cryptocurrency users.

The new sophisticated framework employs TookPS to exfiltrate seed phrases and uses a new OkoSpyware module to monitor Chromium-based browsers and deploy various malware strains, including the Rilide stealer.
It has already targeted hundreds of victims across over 25 countries, with the highest number of affected end users recorded in Brazil, Vietnam, Canada, Mexico and Turkiye. According to Kaspersky experts, the threat remains active and primarily poses a risk to cryptocurrency users.
In January 2026, experts from the Kaspersky Global Research and Analysis Team (GReAT) identified multiple attacks involving a previously unknown malware capable of capturing the contents of cryptocurrency wallet windows. Dubbed Okobot, the new sophisticated malware framework comprises more than 20 malicious payloads and implants designed to perform a wide range of functions, including collecting local files, executing remote commands, downloading arbitrary browser extensions, stealing cryptocurrency wallets, harvesting seed phrases and credentials, recording video and carrying out other malicious activities.
One of the new implants used in the campaign is a loader that modifies browser memory to load and hide malicious extensions. OkoBot also includes a new OkoSpyware module, which captures keystrokes and the video stream of a target application’s window.
Currently available information does not allow the campaign to be attributed to any known crimeware actor with high confidence. However, the techniques and infostealer involved are widely used by Russian-speaking threat actors, and technical analysis has also revealed code artifacts in Russian.
The initial infection typically occurs through two main vectors: ClickFix attacks, in which threat actors use social engineering to trick users into running malicious code, and malware distributed via GitHub under the guise of legitimate software. During the investigation, researchers identified one such case involving a fake installer for SQL Server Management Studio (SSMS), a widely used Microsoft database management tool.
The malicious framework includes SeedHunter, a malware component that monitors active system processes and injects an implant into Trezor Suite, Ledger Wallet, and Ledger Live, – official applications used to manage cryptocurrency assets. When it detects a connected Trezor or Ledger hardware wallet, it triggers the hooked functions to display a hard-coded phishing page aimed at stealing the user’s seed phrase, using a distinct layout for each wallet type.
“The OkoBot campaign has been active for more than a year and remained ongoing as of July 2026. The observed infection vectors strongly suggest that developers are among its primary targets. Of particular concern is the malware’s continued evolution, which indicates that the framework is being actively maintained. As distribution efforts persist, the campaign has the potential to reach more users and expand into additional countries in the near term,” says Dmitry Galov, Head of the Russia and CIS unit at Kaspersky Global Research and Analysis Team.
E-Business
Firm to recruit over 100 professionals to boost NRS e-Invoicing compliance

Afri Invoice, one of Nigeria’s leading accredited e-invoicing service providers, has announced plans to recruit more than 100 professionals nationwide to strengthen support for the Nigeria Revenue Service’s (NRS) mandatory e-invoicing compliance programme.

The recruitment campaign, is aimed at expanding the company’s workforce to meet the growing demand for digital tax infrastructure and help businesses transition smoothly to the country’s evolving e-invoicing regime.
According to the company, the new positions will be spread across Nigeria’s six geopolitical zones to ensure businesses receive timely, localised support as they adapt to the new tax compliance framework.
The vacancies cut across several key departments, including Information Technology (IT), Marketing and Digital Marketing, Audit, Legal, Human Resources and multi-site office operations.
Afri Invoice said applicants are expected to possess relevant professional experience, particularly in managing operations across multiple locations and supporting organisational growth.
The company explained that the latest recruitment drive builds on a similar exercise conducted last year, which significantly expanded its operational reach and increased its capacity to onboard clients nationwide.
With the NRS intensifying the implementation of mandatory e-invoicing, Afri Invoice said it is investing in additional manpower to ensure uninterrupted service delivery, efficient client onboarding and expert technical support for businesses of all sizes.
Speaking on the expansion, the Founder and Chief Executive Officer of Afri Invoice, Mark Odenore, said the company remains committed to helping Nigerian businesses comply with the new tax regulations through innovative technology and professional support.
“As the national drive toward comprehensive e-invoicing gathers momentum under the Nigeria Revenue Service, our mission is to ensure that Nigerian businesses have a reliable, accredited partner to navigate this transition effortlessly,” Odenore said.
He added that recruiting more than 100 professionals across the country’s geopolitical zones would significantly strengthen the company’s ability to provide quality technology solutions and customer support nationwide.
Interested and qualified candidates have been encouraged to submit their applications through Afri Invoice’s official careers portal.
Afri Invoice is an accredited e-invoicing service provider that offers digital solutions designed to simplify financial processes, improve tax transparency and support businesses in complying with national tax regulations while enhancing supply chain and financial management.
E-Business3 days agoKaspersky Identifies Cyberespionage as a Growing Threat Across Africa, Others
Broadcasting3 days agoNBC Files Fresh Appeal against Judgment Barring it from Imposing Fines on Broadcast Stations
News3 days agoINTERPOL Report Shows AI Powers 55% of Cybercrimes in Africa Amid $484m Losses
News3 days agoNigeria Expands Deep-tech Skills Pipeline
Telecom3 days agoWhy Strong Institutions Remain Africa’s True Growth Engine
E-Financial3 days agoNigerians Lost N25.85Bn to Digital Payment Fraud in 2025 –CBN
E-Business2 days agoKaspersky Reveals a New Malicious Framework Targeting Cryptocurrency Users with the Use of OkoSpyware
E-Financial3 days agoNRS Announces 30 Percent Tax on Corporate Crypto Income














