Threats Affecting South Africa
View all threats affecting or targeting South Africa. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting South Africa
Click on any threat for detailed analysis and mitigation recommendations
Striking gold: Inside the GoldDigger Android malware 0 GoldDigger is a sophisticated Android banking trojan targeting mobile banking users primarily in South Africa and Europe, with indications of plans for global expansion. It uses advanced evasion techniques such as a custom packer, anti-debugging, and Frida detection. The malware disguises itself as legitimate airline and shopping apps to deceive victims. It abuses Android Accessibility services to steal credentials, intercept SMS-based two-factor authentication, and perform unauthorized transactions. A notable capability is running targeted banking apps in a virtual environment to intercept API calls and runtime behavior. Communication with command-and-control servers occurs over encrypted WebSocket, enabling screen recording, audio capture, phishing overlays, and remote device control. Join the discussion | AlienVault OTX General | 08/12/2026, 13:20:44 UTC Added: 08/12/2026, 15:41:30 UTC |
Phishing service spoofs RingCentral to steal Microsoft 365 accounts 0 The Greatness phishing-as-a-service (PhaaS) platform targets Microsoft 365 accounts using advanced phishing techniques including adversary-in-the-middle and device-code phishing. It spoofs RingCentral emails to bypass email security filters by exploiting whitelisting and safe-sender list trust. Post-compromise, attackers access Microsoft 365 data and services via stolen authentication tokens. The platform is sold to cybercriminals and has been active since at least mid-2022, targeting users in multiple countries. Researchers recommend auditing safe-sender lists and monitoring suspicious MFA-approved sign-ins. Join the discussion | Bleeping Computer | 08/04/2026, 21:45:36 UTC Added: 08/04/2026, 22:02:01 UTC |
Showing 1 to 2 of 2 results