Threats Tagged 'africa'
View all threats tagged with 'africa'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'africa'
Click on any threat for detailed analysis and mitigation recommendations
This comprehensive analysis covers cyber threats and security issues in the financial industry, both in Korea and globally. It examines malware and phishing cases, lists top malware strains, and provides statistics on leaked Korean accounts. Key issues on the deep and dark web are highlighted, including a major database leak from Indonesia's largest bank, exposing sensitive financial data of approximately 3 million customers. A ransomware attack on a leading African financial services company by INC Ransom group is also detailed, with 100GB of data reportedly stolen. The report emphasizes the potential for widespread damage and chain attacks, urging proactive measures among financial institutions and related companies. Join the discussion | AlienVault OTX General | 01/22/2026, 13:15:09 UTC Added: 01/22/2026, 20:35:56 UTC |
The Brazilian Caminho loader is a sophisticated malware delivery mechanism active since March 2025, leveraging LSB steganography to hide . NET payloads within images hosted on legitimate platforms. It initiates infection via phishing emails containing malicious scripts that download these steganographic images. The loader executes payloads filelessly in memory and establishes persistence using scheduled tasks. Caminho operates as a Loader-as-a-Service, delivering multiple malware families such as Remcos RAT, Xworm, and Katz stealer across South America, Africa, and Eastern Europe. Its use of bulletproof hosting and Portuguese language artifacts indicates a Brazilian origin and professional operation. The campaign targets multiple industries opportunistically without a specific sector focus. The infection chain employs multiple advanced techniques including fileless execution, steganography, and obfuscation, complicating detection and mitigation efforts. European organizations, especially in Eastern Europe, face risks of data theft, espionage, and system compromise. Mitigation requires targeted email security, memory scanning, and monitoring of scheduled tasks for persistence. Join the discussion | AlienVault OTX General | 10/22/2025, 04:00:17 UTC Added: 10/22/2025, 12:09:03 UTC |
Phantom Taurus, a newly identified Chinese state-sponsored threat actor, has been conducting espionage operations targeting government and telecommunications organizations across Africa, the Middle East, and Asia. The group's primary focus includes ministries of foreign affairs, embassies, and military operations, with the objective of gathering sensitive information. Phantom Taurus employs distinctive tactics, techniques, and procedures, including a new malware suite called NET-STAR. This suite consists of three web-based backdoors designed to target Internet Information Services (IIS) web servers. The group has recently shifted from targeting emails to directly accessing databases, demonstrating their ability to adapt and evolve their methods. Phantom Taurus' activities align with Chinese strategic interests, and their infrastructure overlaps with other known Chinese APT groups. Join the discussion | AlienVault OTX General | 09/30/2025, 17:21:27 UTC Added: 09/30/2025, 19:55:06 UTC |
Chinese cyberespionage group APT41 conducted a targeted attack against government IT services in Africa. The attackers used various tools including Impacket, Cobalt Strike, and custom malware for lateral movement, privilege escalation, and data exfiltration. They leveraged DLL sideloading techniques and a compromised SharePoint server as a command and control center. The attack involved credential harvesting, use of web shells, and custom stealers to collect sensitive data. Notable TTPs included using hardcoded internal service names and proxy servers in malware, and exploiting a captive SharePoint server for C2 communication. The incident highlights the importance of comprehensive infrastructure monitoring and proper access controls. Join the discussion | AlienVault OTX General | 07/21/2025, 09:53:00 UTC Added: 07/21/2025, 11:31:04 UTC |
Showing 1 to 4 of 4 results