16
CYBER CRIME & CYBER SECURITY
TRENDS IN AFRICA
It should come as no surprise that the majority of BEC emails
are sent on weekdays. The scammers know that this is when
most businesses would expect emails. And more importantly, most financial transactions can only be cleared during
weekdays. BEC scammers are also most active during a typical
working day. They will generally begin sending emails from
0700 GMT, take break from 1100 until 1400 GMT and then
resume sending until 1800 GMT.
Global Zero-Day Vulnerabilities, Annual Total
TT The highest number of zero-day vulnerabilities was disclosed in 2015,
evidence of the maturing market for research in this area.
70
60
54
50
40
30
20
10
13
15
9
12
2006 2007 2008 2009
BEC scammers keep things simple with most emails containing a single-word subject line. Subjects always contain one
or more of the following words: request, payment, urgent,
transfer, enquiry. Simple, innocuous subject lines are less
likely to arouse suspicion and are also harder to filter.2
Professionalization of Cyber Criminals,
Zero Days Explode
In 2015, the number of zero-day vulnerabilities discovered
more than doubled to 54, a 125 percent increase from the year
before. In 2013, the number of zero-day vulnerabilities (23)
doubled from the year before. In 2014, the number held relatively steady at 24, leading us to conclude that we had reached
a plateau. That
theory was short-lived. The 2015 explosion in zero-day discoveries reaffirms the critical role they play in lucrative targeted
attacks.
2
https://www.symantec.com/connect/blogs/billion-dollar-scams-numbersbehind-bec-fraud
14
23
24
2013
2014
14
8
2010
2011
2012
2015
Given the value of these vulnerabilities, it’s not surprising
that a market has evolved to meet demand. In fact, at the rate
that zero-day vulnerabilities are being discovered, they may
become a commodity product. Targeted attack groups exploit
the vulnerabilities until they are publicly exposed, then toss
them aside for newly discovered vulnerabilities. When The
Hacking Team was exposed in 2015 as having at least six zero
days in its portfolio, it confirmed our characterization of the
hunt for zero days as being professionalized.3
Vulnerabilities can appear in almost any type of software, but
the most attractive to targeted attackers is software that is
widely used. Again and again, the majority of these vulnerabilities are discovered in software such as Internet Explorer and
Adobe Flash, which are used on a daily basis by a vast number
of consumers and professionals in Africa and across the globe.
Four of the five most exploited zero-day vulnerabilities in 2015
were Adobe Flash. Once discovered, the zero days are quickly
added to cyber criminal toolkits and exploited. At this point,
millions will be attacked and hundreds of thousands infected
if a patch is not available, if people have not moved quickly
enough to apply the patch, or if people are left unaware of an
update.
3
https://www.symantec.com/connect/blogs/leaked-hacking-team-windowsvulnerability-could-facilitate-remote-attacks