Newsletter Subscribe
Enter your email address below and subscribe to our newsletter

Check Point® Software Technologies Ltd. has released the Global Threat Index for March 2024. Recent investigations have unveiled cybercriminals’ use files to distribute the Remote Access Trojan (RAT) Remcos, circumventing conventional security protocols.
8 African countries are among the top 20 countries most targeted by cyber criminals. These are Ethiopia (2), Zimbabwe (3), Maldives (4), Kenya (7), Uganda (8), Angola (11), Morocco (17) and Nigeria (20). South Africa has dropped eight places and ranks 64th as the most targeted.
Remcos, a well-known malware dating back to 2016, has resurfaced with a new attack strategy, infiltrating victims’ devices and granting cybercriminals unfettered access. Threat actors have repurposed Remcos from its original use for legitimate remote system management to execute malicious activities, including data exfiltration, keystroke logging, and transmission of sensitive information to designated servers. Moreover, the RAT boasts mass mailer capabilities, enabling the orchestration of distribution campaigns and the establishment of botnets. In March, Remcos ascended to the fourth position on the top malware list, underscoring its escalating threat level.
Maya Horowitz, VP of Research at Check Point Software says, “The evolving tactics of cyberattacks underscore the dynamic nature of cybercriminal strategies. It is imperative for organizations to adopt proactive cybersecurity measures, including robust endpoint protection and comprehensive employee training, to safeguard against evolving threats.”
Check Point’s Ransomware Index sheds light on ransomware activities through “shame sites” operated by double-extortion ransomware groups. Lockbit3 continues to lead the ranking with 12% of reported attacks, followed by Play at 10%, and Blackbasta at 9%. Notably, Blackbasta has surged into the top three, following its recent cyberattack on Scullion Law, a Scottish legal firm.

Last month Education/Research remained in first place in the most attacked industries globally, followed by Government/Military and Communications. In Africa however, Retail/Wholesale, Communications and Utilities are at the top of the list.
Global Industries
Africa Industries
This section features information derived from ransomware “shame sites” operated by double-extortion ransomware groups which posted the names and information of victims. The data from these shame sites carries its own biases, but still provides valuable insights into the ransomware ecosystem.
Lockbit3 accounted for 12% of the published attacks last month, making it the most prevalent ransomware group, followed by Play with 10% and Blackbasta with 9%.
The evolving threat landscape necessitates heightened vigilance and proactive cybersecurity measures across industries in Africa. Organizations should fortify their defenses and prioritize cybersecurity resilience to mitigate the risks posed by emerging malware strains and exploitation tactics.