40 CYBER CRIME & CYBER SECURITY TRENDS IN AFRICA BOT ANALYSIS Bots are programs that are covertly installed on a user’s machine to allow an attacker to remotely control the targeted system through a communication channel, such as internet relay chat (IRC), peer-to-peer (P2P), or HTTP. These channels allow the remote attacker to control a large number of compromised computers over a single, reliable channel in a botnet, which can then be used to launch coordinated attacks. Bots allow for a wide range of functionality and most can be updated to assume new functionality by downloading new code and features. Attackers can use bots to perform a variety of tasks, such as setting up denial-of-service (DoS) attacks against an organization’s website, distributing spam and phishing attacks, distributing spyware and adware, propagating malicious code, and harvesting confidential information from compromised computers that may be used in identity theft, all of which can have serious financial and legal consequences. Top Named Botnet Families for Bots Originating from Africa During the reporting period, Symantec observed that Virut was the top named botnet family for bots originating from Africa with 5,128,775 distinct bots. This accounted for 40% of the total distinct named bots from Africa (see Table 12 and Figure 17). Globally, Virut was the second ranked named botnet family for bots with 24.8 million distinct bots. Virut is a bot that performs various attacks including spreading spam emails, fraud, data theft, and performing DDoS attacks. It was first reported active in 2006. Table 12. Top 10 Named Botnet Families for Bots Originating from Africa—2016 BOTNET FAMILY RANK PERCENTAGE WITHIN AFRICA GLOBAL RANK GLOBAL PERCENTAGE Virut 1 40% 2 30% Conficker 2 17% 1 36% Gamut 3 3% 4 5% Sality 4 2% 9 1% Kelihos 5 2% 5 4% Pony Loader 6 2% 3 9% Keybase 7 <1% 7 2% Kasidet 8 <1% 6 3% Betabot 9 <1% 23 <1% Umbra Loader 10 <1% 18 <1%

Select target paragraph3