16 CYBER CRIME & CYBER SECURITY TRENDS IN AFRICA It should come as no surprise that the majority of BEC emails are sent on weekdays. The scammers know that this is when most businesses would expect emails. And more importantly, most financial transactions can only be cleared during weekdays. BEC scammers are also most active during a typical working day. They will generally begin sending emails from 0700 GMT, take break from 1100 until 1400 GMT and then resume sending until 1800 GMT. Global Zero-Day Vulnerabilities, Annual Total TT    The highest number of zero-day vulnerabilities was disclosed in 2015, evidence of the maturing market for research in this area. 70 60 54 50 40 30 20 10 13 15 9 12 2006 2007 2008 2009 BEC scammers keep things simple with most emails containing a single-word subject line. Subjects always contain one or more of the following words: request, payment, urgent, transfer, enquiry. Simple, innocuous subject lines are less likely to arouse suspicion and are also harder to filter.2 Professionalization of Cyber Criminals, Zero Days Explode In 2015, the number of zero-day vulnerabilities discovered more than doubled to 54, a 125 percent increase from the year before. In 2013, the number of zero-day vulnerabilities (23) doubled from the year before. In 2014, the number held relatively steady at 24, leading us to conclude that we had reached a plateau. That theory was short-lived. The 2015 explosion in zero-day discoveries reaffirms the critical role they play in lucrative targeted attacks. 2 https://www.symantec.com/connect/blogs/billion-dollar-scams-numbersbehind-bec-fraud 14 23 24 2013 2014 14 8 2010 2011 2012 2015 Given the value of these vulnerabilities, it’s not surprising that a market has evolved to meet demand. In fact, at the rate that zero-day vulnerabilities are being discovered, they may become a commodity product. Targeted attack groups exploit the vulnerabilities until they are publicly exposed, then toss them aside for newly discovered vulnerabilities. When The Hacking Team was exposed in 2015 as having at least six zero days in its portfolio, it confirmed our characterization of the hunt for zero days as being professionalized.3 Vulnerabilities can appear in almost any type of software, but the most attractive to targeted attackers is software that is widely used. Again and again, the majority of these vulnerabilities are discovered in software such as Internet Explorer and Adobe Flash, which are used on a daily basis by a vast number of consumers and professionals in Africa and across the globe. Four of the five most exploited zero-day vulnerabilities in 2015 were Adobe Flash. Once discovered, the zero days are quickly added to cyber criminal toolkits and exploited. At this point, millions will be attacked and hundreds of thousands infected if a patch is not available, if people have not moved quickly enough to apply the patch, or if people are left unaware of an update. 3 https://www.symantec.com/connect/blogs/leaked-hacking-team-windowsvulnerability-could-facilitate-remote-attacks

Select target paragraph3