CYBER CRIME & CYBER SECURITY
TRENDS IN AFRICA
37
During the reporting period, Africa was a large source of the W32.SillyFDC.BDP Attack, System Infected:
Dark Comet RAT Activity, and Trojan.Cridex Activity (see Figure 14). The following is a summary of the
findings:
• Eighty-five percent of the W32.SillyFDC.BDP Attack events were from Africa. As mentioned, W32.
SillyFDC.BDP is a worm that spreads through removable media and can download other files onto
the compromised computer.6
• Africa was the source of 33% of the global System Infected: Dark Comet RAT Activity attack
incidents. Dark Comet RAT is a remote access tool that has been tied to a number of global incidents.7,8
• Africa was the source of 15% of the global Trojan.Cridex9 activity. Trojan.Cridex is a widespread
banking Trojan that may infect the targeted computer with a bot program.
Figure 14. Percentage of Malware Originating from Africa with Global Comparison—2016
85%
W32.SillyFOC.BDP Attack
15%
Trojan.Cridex Activity
85%
3%
System Infected: Backdoor Houdini Activity
97%
7%
W32.Qakbot Activity
93%
4%
System Infected: W32.Downadup Activity
96%
33%
System Infected : Dark Comet RAT Activity
67%
<1%
Possible Conficker Infection
99%
7%
System Infected: Trojan.Malscript activity
93%
<1%
System Infected: Oownloader.Upatre Activity
99%
5%
System Infected: Backdoor.Ratenjay RAT Activity
0%
95%
20%
40%
60%
Africa
Rest of the World
Top Malware Targeting Africa
During the reporting period, Symantec observed 24 million malware incidents targeting Africa with
3,490 different malware signatures. This accounted for 2.5% of the global malware total. The top
malware targeting Africa was Downloader.Dromedan Activity, accounting for 15% of the targeted total
(see Table 11 and Figure 15). Downloader.Dromedan Activity10, indicates the presence of a malicious
Trojan on the affected computer. This Trojan downloads additional files to further compromise the
affected computer.
6
7
8
9
10
15%
http://www.symantec.com/security_response/writeup.jsp?docid=2011-031106-4835-99
https://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=26653
http://www.symantec.com/connect/blogs/darkcomet-rat-it-end
https://www.symantec.com/security_response/writeup.jsp?docid=2015-012314-0117-99
https://www.symantec.com/security_response/writeup.jsp?docid=2011-101915-4058-99
80%
100%