{"id":32140,"date":"2020-02-25T14:03:39","date_gmt":"2020-02-25T14:03:39","guid":{"rendered":"https:\/\/www.intelligentcio.com\/africa\/?p=32140"},"modified":"2020-02-27T10:37:11","modified_gmt":"2020-02-27T10:37:11","slug":"south-african-industries-under-attack-from-cybercriminals","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2020\/02\/25\/south-african-industries-under-attack-from-cybercriminals\/","title":{"rendered":"South African industries under attack from cybercriminals"},"content":{"rendered":"\n<p>Mimecast, a leading email and data security company,<a> <\/a>has announced the availability of the <em>Mimecast Threat Intelligence Report: RSA Conference Edition<\/em>. The report is designed to provide technical analysis from Mimecast threat researchers on major campaigns carried out by threat actors, trends that are emerging from these attacks and an assessment of likely future trends given threat actors\u2019 current behavior, events and technology. <\/p>\n\n\n\n<p>The report uncovers the resurgence of Emotet as well as a combination of simplistic, low effort and low-cost attacks, and highly complex, targeted campaigns. Additionally, Mimecast has launched the Mimecast Threat Intelligence Hub to house specific threat intelligence insights, reports and vulnerability discoveries from the Mimecast Threat Intelligence Research Team.<\/p>\n\n\n\n<p>The Mimecast <em>Threat Intelligence Report: RSA\nConference Edition<\/em>\nprovides analysis of 202 billion emails processed by Mimecast for its\ncustomers globally during the period from October through December 2019 showed\nthat 92 billion of which were rejected. <\/p>\n\n\n\n<p>The team\ndiscovered and examined four main categories of attack types throughout the\nreport: spam, impersonation, opportunistic and targeted. Compared to previous\nquarters, Mimecast researchers noted a marked difference in the more\nsignificant attacks conducted &#8211; the attacks targeted a wider range of companies\nacross various sectors and for shorter periods of time than in previous\nquarters. <\/p>\n\n\n\n<p>The one sector\nthat was particularly targeted this quarter was the retail industry, accounting\nfor almost a third of the most significant campaign activity conducted by\nthreat actors globally. However, given the holiday gift-giving season from\nOctober to December, some of this increase was to be expected.&nbsp; <\/p>\n\n\n\n<p>In South Africa, the previous Mimecast <em>Threat Intelligence Report<\/em> for the July to September\n2019 period uncovered an extensive cyberattack campaign against the banking\nsector. <\/p>\n\n\n\n<p>In its latest report, Mimecast found that cyberattack\ncampaigns have expanded to other industry sectors as South Africa suffered 14\nmajor cyberattacks targeting the retail, manufacturing, transport, banking and\nmining sectors. The report shows that attacks occurred within a short time on\ntwo key dates when organisations were repeatedly targeted. <\/p>\n\n\n\n<p>Given the similarity in attack vectors and the make-up\nof the attacks, it is highly likely the threat actors are the same for each and\nall of the periods of activity noted against the various sectors attacked. The\nreport states that the resources required to target several sectors of the\neconomy and multiple organisations would be considerable.<\/p>\n\n\n\n<p>The most\nprominent observation of this quarter\u2019s research was the widespread global\ndeployment of the Emotet \u2018dropper\u2019 banking malware, which had been seemingly\ninactive during the previous four months. There were 61 significant campaigns\nidentified, marking a 145% increase over last quarter despite fewer emails\nbeing analysed during the period.&nbsp;Emotet was a key driver in this spike,\nas the banking trojan\/malware was a component in almost every attack\nidentified.&nbsp; This massive increase in activity is highly likely to\nbe an indication of threat actors refocusing their efforts from impersonation\nto exploiting the current effectiveness of ransomware.<\/p>\n\n\n\n<p>\u201cIt\u2019s no\nsurprise that threat actors are using a combination of simplistic and\nsophisticated attacks to gain access to organisations,\u201d said Josh Douglas, Vice\nPresident of Threat Intelligence at Mimecast.&nbsp;<\/p>\n\n\n\n<p>\u201cThat\u2019s also\nlikely why we saw such a huge spike in the recently dormant Emotet campaign \u2013\nthey\u2019re attempting to gain as much attack space as possible to land other\nsophisticated attacks or hold organisations hostage. These reports offer\norganisations a global view on how threats are evolving so they can make\ninformed decisions on how to best strengthen their cyber resilience posture.\u201d<\/p>\n\n\n\n<p>Additional key findings outlined in the report:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>The transportation, storage and delivery and retail and wholesale sectors were disproportionately attacked this past quarter due to the holiday season <\/li><li>Emotet has been utilised far more extensively and  has been seen in widespread campaigns against all sectors of the global economy. This discovery demonstrates a level of sophistication that goes beyond an opportunistic cybercriminal. In addition, due to the variety of      businesses attacked, it\u2019s highly likely the attacks continue to be carried      out by highly organised criminal groups for monetary gain.<\/li><li>File compression continued to be an attack format of choice, but Emotet activity via DOC and DOCX formats substantially increased<\/li><li>Although the number of impersonation attacks is slightly fewer, they remain a key attack vector. Impersonation attacks now include a range of voice messaging and a generally less coercive form of      communication, which presents as a more nuanced and persuasive threat<\/li><li>Relying on human error for success, bulk emailing remained a significant, high volume means to distribute malware. This trend will continue as it\u2019s a powerful threat vector that can be deployed in huge volumes, increasing the possibility of success for threat actors.<\/li><\/ul>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mimecast, a leading email and data security company, has announced the availability of the Mimecast Threat Intelligence Report: RSA Conference Edition. The report is designed to provide technical analysis from Mimecast threat researchers on major campaigns carried out by threat actors, trends that are emerging from these attacks and an assessment of likely future trends [&hellip;]<\/p>\n","protected":false},"author":25,"featured_media":32141,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,275,399,19,54,9059,262],"tags":[12690,12470,10056,9659,484,453],"class_list":["post-32140","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-intelligent-technology-newsletter","category-more-news","category-regional-news","category-research","category-south-africa","category-used","tag-doc","tag-docx","tag-emotet","tag-josh-douglas","tag-mimecast","tag-south-africa"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/32140","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=32140"}],"version-history":[{"count":4,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/32140\/revisions"}],"predecessor-version":[{"id":32145,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/32140\/revisions\/32145"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/32141"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=32140"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=32140"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=32140"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}