CYBER CRIME & CYBER SECURITY TRENDS IN AFRICA 37 During the reporting period, Africa was a large source of the W32.SillyFDC.BDP Attack, System Infected: Dark Comet RAT Activity, and Trojan.Cridex Activity (see Figure 14). The following is a summary of the findings: • Eighty-five percent of the W32.SillyFDC.BDP Attack events were from Africa. As mentioned, W32. SillyFDC.BDP is a worm that spreads through removable media and can download other files onto the compromised computer.6 • Africa was the source of 33% of the global System Infected: Dark Comet RAT Activity attack incidents. Dark Comet RAT is a remote access tool that has been tied to a number of global incidents.7,8 • Africa was the source of 15% of the global Trojan.Cridex9 activity. Trojan.Cridex is a widespread banking Trojan that may infect the targeted computer with a bot program. Figure 14. Percentage of Malware Originating from Africa with Global Comparison—2016 85% W32.SillyFOC.BDP Attack 15% Trojan.Cridex Activity 85% 3% System Infected: Backdoor Houdini Activity 97% 7% W32.Qakbot Activity 93% 4% System Infected: W32.Downadup Activity 96% 33% System Infected : Dark Comet RAT Activity 67% <1% Possible Conficker Infection 99% 7% System Infected: Trojan.Malscript activity 93% <1% System Infected: Oownloader.Upatre Activity 99% 5% System Infected: Backdoor.Ratenjay RAT Activity 0% 95% 20% 40% 60%  Africa  Rest of the World Top Malware Targeting Africa During the reporting period, Symantec observed 24 million malware incidents targeting Africa with 3,490 different malware signatures. This accounted for 2.5% of the global malware total. The top malware targeting Africa was Downloader.Dromedan Activity, accounting for 15% of the targeted total (see Table 11 and Figure 15). Downloader.Dromedan Activity10, indicates the presence of a malicious Trojan on the affected computer. This Trojan downloads additional files to further compromise the affected computer. 6 7 8 9 10 15% http://www.symantec.com/security_response/writeup.jsp?docid=2011-031106-4835-99 https://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=26653 http://www.symantec.com/connect/blogs/darkcomet-rat-it-end https://www.symantec.com/security_response/writeup.jsp?docid=2015-012314-0117-99 https://www.symantec.com/security_response/writeup.jsp?docid=2011-101915-4058-99 80% 100%

Select target paragraph3