Tag: africa

SideWinder APT Strikes Middle East and Africa With Stealthy Multi-Stage Attack
News

SideWinder APT Strikes Middle East and Africa With Stealthy Multi-Stage Attack

Attacks on prominent targets and vital infrastructure in the Middle East and Africa have been launched by an advanced persistent threat (APT) actor suspected of having connections to India. The organization identified as SideWinder—also known as APT-C-17, Baby Elephant, Hardcore Nationalist, Leafperforator, Rattlesnake, Razor Tiger, and T-APT-04—has been linked to the activity. The group's use of malicious LNK files and scripts as infection vectors, public exploits, and public remote access tools (RATs) may give the impression that they are a low-skilled player, but a closer look at their operational details reveals their true skills. According to Kaspersky experts Vasily Berdnikov and Giampaolo Dedola read more about SideWinder APT Strikes Middle East and Africa With Stealthy Multi...
Bluebottle Cybercrime Group Preys on Financial Sector in French-Speaking African Nations
Risk, Security

Bluebottle Cybercrime Group Preys on Financial Sector in French-Speaking African Nations

A series of targeted attacks against the financial sector in Francophone nations in Africa from at least July 2022 to September 2022 have been connected to the cybercrime organisation known as Bluebottle. The Hacker News received a report from Symantec, a division of Broadcom Software. "The organisation makes considerable use of living-off-the-land, dual use tools, and commodity malware, with no unique malware deployed in this campaign," the report stated. The cybersecurity company claimed that the activity aligns with a threat cluster known as OPERA1ER, which between 2018 and 2022 launched hundreds of assaults on banks, financial services providers, and telecom firms in Africa, Asia, and Latin America. The toolset employed, the attack infrastructure, the lack of custom malware, ...