The masterminds behind the hackers

0
130
The masterminds behind the hackers

Cyber attacks on African organisations have surged past global averages. This has placed the continent firmly in the crosshairs of the world’s most dangerous threat actors.

In the first quarter of 2025 alone, Africa experienced 3,286 attacks per organisation per week. This was the highest average of any region globally, according to cybersecurity platform provider Check Point Software.

The company’s Q1 2025 Global Cyber Attack Report shows that Nigeria recorded 4,388 attacks per week, Angola reached 4,727, and Kenya stood at 4,004. Even South Africa, with a relatively modest 1,884 attacks weekly, saw a staggering 69% year-on-year increase.

These figures reflect a dramatic escalation in both volume and sophistication of attacks. The masterminds behind the hackers now range from state-sponsored espionage units to loosely organised digital extortionists. Africa has become both a testing ground and a soft target.

Inexperienced hackers as masterminds?

The evolving threat landscape has turned even amateur efforts into real dangers. However, professionalised, persistent actors pose the deepest risks. “Script kiddies” still play a role. This term refers to inexperienced attackers who use plug-and-play hacking tools.

During a media briefing in Johannesburg, Check Point shared an example. A few young Kenyans bought hacking tools online and mounted attacks from their homes. They lacked sophistication but were still very successful.

Hendrik de Bruin, a Security Consulting Specialist at Check Point Software, commented:

That speaks to the fact that you don’t really need to have a mastermind to perpetrate successful cybercrime. But the real danger lies in the more sophisticated operations.

The masterminds behind larger-scale cyber attacks

When we talk about these larger-scale cyber attacks, we begin to address Advanced Persistent Threats (APTs) and state-sponsored campaigns.

One of the most notable examples is APT41, a cyber threat group believed to operate on behalf of the Chinese government. The masterminds behind the hackers in this case are known for exceptional skill and adaptability.

APT41 is widely regarded as one of the most sophisticated and versatile APT groups globally. It has a dual focus: cyber espionage and financially motivated cybercrime. This group is linked to recent breaches in Kenya. In one case, attackers remained inside a government network for weeks and had full administrative access.

APT41 relies on a well-documented catalogue of TTPs – techniques, tactics and procedures. These allow analysts, such as those at Check Point, to match digital fingerprints to known attacks. The Kenyan breach bore all the telltale signs. This rise in attacks reflects several critical issues. These include vulnerabilities in infrastructure, rapid digital transformation without proper security controls and poor regulation of cyber governance.

Low-hanging fruit for attackers

Digitisation is often pursued without adequate focus on security. This affects the government, the public sector and the private sector alike.

Across the board, people are abandoning paper-based processes. They adopt cloud solutions and similar technologies. However, these steps are not always taken securely. This creates low-hanging fruit for attackers.

South Africa illustrates this paradox well. The country has relatively advanced connectivity and high mobile penetration. Ironically, this makes it more vulnerable. Too often, organisations treat cybersecurity as a tick-box exercise. Someone might say, “You need to have a firewall”, so the organisation buys the cheapest option and marks it done.

The consequences are being felt across all sectors. Globally, education leads the pack with 4,484 weekly attacks per organisation. In Africa, telecommunications companies are emerging as prime targets. Their critical infrastructure and rich user databases make them attractive.

Motives behind the hacking masterminds

Recent breaches have hit South Africa’s MTN, Namibia’s Telecom Namibia and Kenya’s South Sea.

De Bruin points to a mix of motives: espionage, activism and opportunism:

As geopolitical tensions rise, we see an increase in these NATION-STATES attacking each other. They don’t necessarily use ransomware. Instead, they use wipers to make sure that all the data has been removed.

Internal threats are also on the rise. Insider risks are harder to measure but can be even more damaging. De Bruin shared one example. A supplier to a Brazilian bank was bribed with $900 to hand over login credentials. The resulting damage amounted to a $140-million attack.

We also see a massive TACKLE on identity-related attacks. You can purchase credentials on the dark web for about $5.

In conclusion

While some attacks are meticulously planned by elite, state-sponsored teams, others are more decentralised and opportunistic. They often rely on a chain of small compromises.

Supply chain infiltration is identified as a growing tactic. Rather than attacking a bank individually, they find an IT service provider for the bank. They get access to the provider’s infrastructure, and by extension, access to multiple other infrastructures. This context reveals the masterminds behind the hackers.

These cyber actors are a hybrid of software, strategy, and subterfuge. Sometimes they operate under a nation’s flag. Other times, they work without one. This also shows how inadequate traditional defences have become. Firewalls, anti-virus software, and patching no longer offer enough protection.

A “prevention-first” approach is recommended. This includes multi-layered defences, employee training, zero-trust architectures, regular vulnerability testing and response protocols that assume a breach has already occurred.


Arthur Goldstuck | CEO | World Wide Worx  | Editor-in-Chief | Gadget.co.za | mail me |




LEAVE A REPLY

Please enter your comment!
Please enter your name here