Cyberattacks Now Targeting High-Profile Individuals And Businesses – Report

Kenyans have been alerted to a rising threat of sophisticated cyberattacks, as attackers shift their focus to high-profile individuals and businesses rather than those with lower turnovers.

According to the 2023 Annual Cybersecurity Report by Trend Micro, criminals are now prioritizing high-value targets in Kenya for greater returns.

The nature of these attacks has evolved, becoming more sophisticated and harder to detect,” notes the study in part.

Trend Micro, a global cybersecurity firm, reports that online criminals remain active in Kenya despite several arrests and convictions.

Gareth Redelinghuys, Country Managing Director for the African Cluster at Trend Micro, stated, “We blocked approximately 37 million email threats, over half a million malicious Uniform Resource Locators (URLs) in the country.”

In the same period, more than one million malicious attacks on mobile apps used by Kenyan businesses and consumers were thwarted.

This trend signifies that cybercriminals are aiming for quality over quantity, targeting fewer but more lucrative victims.

“Our latest data shows that threat actors are fine-tuning their operations, shifting away from large-scale attacks, and instead focusing on a smaller range of targets but with higher victim profiles for maximum gain with minimum effort,” Redelinghuys emphasized in a media statement.

To execute their schemes, cybercriminals are using advanced techniques like Living-Off-The-Land Binaries and Scripts, which exploit non-malicious files native to operating systems to mask their activities.

Globally, ransomware detections have significantly decreased from 2021 to 2023, averaging less than half the detections recorded in 2020.

The report also notes a rise in Trojan FRS threats globally, indicating that attackers are getting better at evading initial detection.

In 2023, several ransomware families used remote and intermittent encryption, as well as unmonitored virtual machines, to bypass Endpoint Detection and Response (EDR) systems.

By using less content during encryption, these attacks minimize the chance of triggering detection mechanisms.

Prominent ransomware groups such as Clop and BlackCat were particularly active last year.

Clop exploited significant vulnerabilities, while BlackCat introduced a new variant and used regulatory requirements to pressure victims into quicker compliance.

Email threats in Kenya have also evolved towards more sophisticated methods. Although email threat detections dropped from over 66 million in 2021 to 37 million in 2023, the increase in malware detection indicates a strategic shift by attackers.

Cybercriminals are now conducting more targeted operations, like Business Email Compromise (BEC) schemes, which are designed to appear legitimate and evade scrutiny.

“IT leaders must refine their processes and protocols to combat these persistent and increasingly sophisticated attacks with efficiency,” urged Zaheer Ebrahim, Solutions Architect for the Middle East and Africa at Trend Micro.

“As attacks become more difficult to detect, the cost of successful breaches will rise,” Ebrahim added.

Kenya’s Computer Misuse and Cybercrime Act provides legal protection for its citizens against various forms of online harassment.

READ, ALSO;

Ruto Calls for Urgent Reforms

Leave a Reply

Your email address will not be published. Required fields are marked *