CYBER CRIME & CYBER SECURITY
TRENDS IN AFRICA
39
Symantec observed that Africa was a large target of System Infected: Backdoor Houdini Activity, VBS.
Dunihi!lnk, and W32.Chir.B@mm global malware incidents during the reporting period (see Figure 16).
The summary details are as follows:
• Thirty percent of global System Infected: Backdoor Houdini Activity events targeted Africa.
Backdoor Houdini is a Trojan that opens a backdoor on the compromised computer. The malicious
software may then download other programs.
• Africa was the target of 28% of the global VBS.Dunihi!lnk malware incidents. This signature
detects .lnk files created by the VBS.Dunihi worm.11 Microsoft Windows uses the .lnk file extension
for shortcuts to local files and executable files. The VBS.Dunihi worm spreads by copying itself
onto removable drives. It creates .lnk files to replace all the files in the removable drive and once
executed, it copies itself onto a computer.
• Twenty-three percent of the global W32.Chir.B activity targeted Africa during the reporting
period. W32.Chir.B W32 is a mass-mailing worm that spreads by sending emails to address book
contacts on the compromised computer.12
Figure 16. Percentage of Malware Targeting Africa with Global Comparison—2016
Downloader.Dromedan Activity
10%
90%
VBS.Dunihi!lnk
28%
System Infected: Backdoor Houdini Activity
72%
30%
Trojan.Gen
70%
3%
W32.Ramnit!html
97%
11%
89%
W32.Chir.B@mm
23%
System Infected: Fake Plugin Activity
77%
4%
Generic W32.Sality Attack
96%
10%
W32.Ramnit.B
90%
18%
System Infected: Downloader.Upatre Activity
82%
5%
0%
95%
20%
40%
Africa
11
12
http://www.symantec.com/security_response/writeup.jsp?docid=2013-091222-3652-99
https://www.symantec.com/security_response/writeup.jsp?docid=2002-072920-3942-99
60%
Rest of the World
80%
100%