40
CYBER CRIME & CYBER SECURITY
TRENDS IN AFRICA
BOT ANALYSIS
Bots are programs that are covertly installed on a user’s machine to allow an attacker to remotely
control the targeted system through a communication channel, such as internet relay chat (IRC),
peer-to-peer (P2P), or HTTP. These channels allow the remote attacker to control a large number of
compromised computers over a single, reliable channel in a botnet, which can then be used to launch
coordinated attacks.
Bots allow for a wide range of functionality and most can be updated to assume new functionality
by downloading new code and features. Attackers can use bots to perform a variety of tasks, such
as setting up denial-of-service (DoS) attacks against an organization’s website, distributing spam and
phishing attacks, distributing spyware and adware, propagating malicious code, and harvesting confidential information from compromised computers that may be used in identity theft, all of which can
have serious financial and legal consequences.
Top Named Botnet Families for Bots Originating from Africa
During the reporting period, Symantec observed that Virut was the top named botnet family for bots
originating from Africa with 5,128,775 distinct bots. This accounted for 40% of the total distinct named
bots from Africa (see Table 12 and Figure 17). Globally, Virut was the second ranked named botnet
family for bots with 24.8 million distinct bots.
Virut is a bot that performs various attacks including spreading spam emails, fraud, data theft, and
performing DDoS attacks. It was first reported active in 2006.
Table 12. Top 10 Named Botnet Families for Bots Originating from Africa—2016
BOTNET FAMILY
RANK
PERCENTAGE
WITHIN AFRICA
GLOBAL
RANK
GLOBAL PERCENTAGE
Virut
1
40%
2
30%
Conficker
2
17%
1
36%
Gamut
3
3%
4
5%
Sality
4
2%
9
1%
Kelihos
5
2%
5
4%
Pony Loader
6
2%
3
9%
Keybase
7
<1%
7
2%
Kasidet
8
<1%
6
3%
Betabot
9
<1%
23
<1%
Umbra Loader
10
<1%
18
<1%