logo
Kaspersky: Advanced Persistent Threat (APT41) targets Southern African organisation in espionage attack

Kaspersky: Advanced Persistent Threat (APT41) targets Southern African organisation in espionage attack

Zawya2 days ago
Kaspersky Managed Detection and Response experts (www.Kaspersky.co.za) have observed a cyber espionage attack on an organisation in Southern African and have linked it to the Chinese-speaking APT41 group. Although the threat actor has shown limited activity in Southern Africa, this incident reveals that the cyber attackers have targeted government IT services in one of the countries in the region, attempting to steal sensitive corporate data — including credentials, internal documents, source code, and communications.
APT (Advanced Persistent Threat) is a category of threat actors known for carrying out concerted, stealthy, and ongoing attacks against specific organisations, as opposed to opportunistic, isolated incidents that account for most cybercriminal activity. The adversaries' techniques observed during the attack in Southern Africa allowed Kaspersky to attribute it to the Chinese-speaking APT41 group with a high confidence. The primary goal of the attack was cyber espionage, which is typical for this threat actor. The attackers attempted to collect sensitive data from the machines they compromised within the organisation's network.
It is noteworthy that APT41 typically has been showing quite limited activity in the Southern African region. APT41 specialises in cyber espionage and targets organisations across various industries, including telecommunications providers, educational and healthcare institutions, IT, energy, and other sectors, with known activity in at least 42 countries.
Based on Kaspersky experts' analysis, the attackers may have gained access to the organisation's network through a web server exposed to the Internet. Using a credential harvesting technique – known in professional terms as registry dumping – the attackers obtained two corporate domain accounts: one with local administrator rights on all workstations and another belonging to a backup solution, which had domain administrator privileges. These accounts allowed the attackers to compromise additional systems within the organisation.
One of the stealers used for data collection was a modified Pillager utility, designed for exporting and decrypting data. The attackers compiled its code from an executable file into a Dynamic Link Library (DLL). With it, they aimed to gather saved credentials from browsers, databases, administrative tools, as well as project source code, screenshots, active chat sessions and their data, email correspondence, lists of installed software, operating system credentials, Wi-Fi credentials, and other information.
The second stealer used during the attack was Checkout. In addition to saved credentials and browser history, it was also capable of collecting information on downloaded files and browser-stored credit card data. The attackers also used the RawCopy utility and a version of Mimikatz compiled as a Dynamic Link Library (DLL) to dump registry files and credentials, as well as Cobalt Strike for Command and Control (C2) communication on compromised hosts.
'Interestingly, as one of their C2 communication channels besides Cobalt Strike, the attackers chose the SharePoint server within the victim's infrastructure. They communicated with it using custom C2 agents connected with a web-shell. They may have chosen SharePoint because it was an internal service already present in the infrastructure and unlikely to raise suspicion. Moreover, in that case, it probably offered the most convenient way to exfiltrate data and control compromised hosts through a legitimate communication channel,' explains Denis Kulik, Lead SOC Analyst at Kaspersky Managed Detection and Response service.
'In general, defending against such sophisticated attacks is impossible without comprehensive expertise and continuous monitoring of the entire infrastructure. It is essential to maintain full security coverage across all systems with solutions capable of automatically blocking malicious activity at an early stage — and to avoid granting user accounts excessive privileges,' comments Denis Kulik.
To mitigate or prevent similar attacks, organisations are advised to follow these best practices:
Ensure that security agents are deployed on all workstations within the organisation without exception, to enable timely incident detection and minimise potential damage.
Review and control service and user account privileges, avoiding excessive rights assignments – especially for accounts used across multiple hosts within the infrastructure.
To protect the company against a wide range of threats, use solutions from the Kaspersky Next (https://apo-opa.co/44EI2e3) product line that provide real-time protection, threat visibility, investigation and the response capabilities of EDR and XDR for organisations of any size and industry. Depending on your current needs and available resources, you can choose the most relevant product tier and easily migrate to another one if your cybersecurity requirements are changing.
Adopt managed security services by Kaspersky such as Compromise Assessment (https://apo-opa.co/4m8aElL), Managed Detection and Response (MDR) (https://apo-opa.co/4m6do37) and / or Incident Response (https://apo-opa.co/44VsAsP), covering the entire incident management cycle – from threat identification to continuous protection and remediation. They help to protect against evasive cyberattacks, investigate incidents and get additional expertise even if a company lacks cybersecurity workers.
Provide your InfoSec professionals with an in-depth visibility into cyberthreats targeting your organisation. The latest Kaspersky Threat Intelligence (https://apo-opa.co/3TQbRlK) will provide them with rich and meaningful context across the entire incident management cycle and helps them identify cyber risks in a timely manner.
A detailed analysis of the incident is available on Securelist (https://apo-opa.co/46mfGGS).
Kaspersky Managed Detection and Response service monitors suspicious activity and helps organisations respond swiftly to minimise impact. This is a part of Kaspersky Security Services, a team delivering hundreds of information security projects every year for Fortune Global 500 organisations: incident response, managed detection, SOC consulting, red teaming, penetration testing, application security, digital risks protection.
Distributed by APO Group on behalf of Kaspersky.
For further information please contact:
Nicole Allman
nicole@inkandco.co.za
Social Media:
Facebook: https://apo-opa.co/414B7bE
X: https://apo-opa.co/4lYjIJQ
YouTube: https://apo-opa.co/452Opa9
Instagram: https://apo-opa.co/4lGn6JK
Blog: https://apo-opa.co/4l8kweB
About Kaspersky:
Kaspersky is a global cybersecurity and digital privacy company founded in 1997. With over a billion devices protected to date from emerging cyberthreats and targeted attacks, Kaspersky's deep threat intelligence and security expertise is constantly transforming into innovative solutions and services to protect individuals, businesses, critical infrastructure, and governments around the globe. The company's comprehensive security portfolio includes leading digital life protection for personal devices, specialized security products and services for companies, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. We help millions of individuals and over 200,000 corporate clients protect what matters most to them. Learn more at www.Kaspersky.co.za.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Ambassador Yin Chengwu attended Liberia Technology Summit 2025
Ambassador Yin Chengwu attended Liberia Technology Summit 2025

Zawya

time11 hours ago

  • Zawya

Ambassador Yin Chengwu attended Liberia Technology Summit 2025

On July 21, Ambassador Yin Chengwu attended the Liberia Technology Summit 2025 and delivered a speech. The event was also attended by Hon. Haja Mamaka Bility, Acting Minister of States, Hon. Augustine K. Ngafuan, Minister of Finance and Development Planning, Hon. Sekou M. Kromah, Minister of Post and Telecommunications. Representatives from relevant UN agencies and diplomatic missions in Liberia. Yin highlighted the outcomes of the Ministerial Meeting of Coordinators on the Implementation of the Follow-up Actions of the Forum on China-Africa Cooperation and China's achievements in science and technology. He pointed out that China will establish a global scientific research fund and increase science and technology assistance to developing countries, making technological progress benefits all humanity. He expressed China is willing to strengthen scientific and technological innovation cooperation with Liberia, so as to make it a new engine of China-Liberia strategic partnership. Distributed by APO Group on behalf of Embassy of the People's Republic of China in the Republic of Liberia.

Absa and Visa extend strategic partnership to advance growth and innovation across Africa
Absa and Visa extend strategic partnership to advance growth and innovation across Africa

Zawya

time14 hours ago

  • Zawya

Absa and Visa extend strategic partnership to advance growth and innovation across Africa

Nairobi, Kenya – Absa and Visa have renewed their strategic partnership to accelerate the development of innovative, inclusive, secure, and digitally enabled financial payment ecosystems across Absa's Regional Operations (ARO) which incorporates Absa's presence outside South Africa. The agreement, formalised at a signing ceremony in Johannesburg, marks a significant milestone in a relationship that has driven innovation and financial inclusion across the continent for many years. Anchored in a shared vision to transform how individuals and businesses engage with financial services, the renewed partnership will deepen collaboration across digital infrastructure expansion, small business enablement, and customer-centric innovation in the Cards and Payments domain. 'This regional expansion marks an exciting new chapter in our partnership with Absa — one that continues to challenge conventions and redefine the possibilities within financial services,' said Michael Berner, Head of Southern and East Africa at Visa. 'We share a strong commitment to growing digital access across the region. Absa's leadership in innovation drives real impact, and we're proud to support their momentum with Visa's global expertise and technology as they deliver seamless experiences to their customers.' The partnership has already delivered several market-first innovations for customers across Africa. Absa became the first bank in multiple African markets to launch Visa Direct enabling card to card domestic and international payments. The introduction of Visa Signature and Infinite metal cards set a new benchmark in premium banking with exclusive lifestyle benefits. Additionally, Absa Pay issuer wallets expanded digital payment experiences, marking a first in Mauritius. "Through our strategic partnership with Visa, we're building a financial ecosystem that reflects the pace of today's African economies. In every market we operate in, we connect deeply with local communities to ensure that we deliver financial solutions that respond to the evolving needs and realities of our customers," said Saviour Chibiya, Chief Executive for Absa Regional Operations. In 2025, Absa also launched Visa Business Credit Cards, designed to solve real-world challenges for businesses and entrepreneurs. These cards offer enhanced value through tailored benefits, spend controls, and access to Visa Spend Clarity Plus – a first in Sub-Saharan Africa – enabling virtual card issuance and advanced expense management for business clients. The renewed agreement places strong emphasis on enabling small and medium-sized enterprises (SMEs) with targeted solutions to improve access to credit, expand payment acceptance and support responsible lending. 'Partnerships like this are central to how we scale impact across the continent,' said Omar Baig, Managing Executive for Absa Regional Operations Retail & Business Banking. 'Visa brings global technology, insights, and capabilities that help us deliver locally relevant solutions, from expanding domestic and international payment capabilities for individuals and businesses, enabling financial access to underserved communities to deepening digital access for our customers. As we grow our presence across Africa, this renewed agreement helps us to move with greater speed and coordination to meet the needs of the communities we serve.' 'Our partnership with Absa stands as a powerful testament to the shared vision between our two brands — one that champions a secure, inclusive, and resilient digital payments ecosystem. We are proud of what we've built together in South Africa, and excited to deepen this collaboration across the continent as we continue driving innovation and financial inclusion at scale,' said Lineshree Moodley, Country Head for Visa South Africa. As Absa and Visa move forward, the partnership will focus on co-developing solutions that drive digital commerce, enhance customer experiences, and support inclusive economic growth. Together, Absa and Visa are shaping the future of finance in Africa – one innovation, one business, and one customer at a time. About Visa Visa Inc. (NYSE: V) is a world leader in digital payments, facilitating transactions between consumers, merchants, financial institutions, and government entities across more than 200 countries and territories. Our mission is to connect the world through the most innovative, reliable, and secure payment network, enabling individuals, businesses, and economies to thrive. About Absa Group Limited Absa Group Limited ('Absa Group') is listed on the Johannesburg Stock Exchange and is one of Africa's largest diversified financial services groups. Absa Group offers an integrated set of products and services across personal and business banking, corporate and investment banking, wealth and investment management and insurance. Absa Group owns majority stakes in banks in Botswana, Ghana, Kenya, Mauritius, Mozambique, Seychelles, South Africa, Tanzania (Absa Bank Tanzania and National Bank of Commerce), Uganda and Zambia and has insurance operations in Kenya and South Africa. Absa also has offices in the People's Republic of China, Namibia, Nigeria and the United States, as well as securities entities in the United Kingdom and the United States, along with technology support colleagues in the Czech Republic.

Nice Deer receives FRA approval to launch Egypt's first digital factoring platform for medical claims
Nice Deer receives FRA approval to launch Egypt's first digital factoring platform for medical claims

Zawya

time14 hours ago

  • Zawya

Nice Deer receives FRA approval to launch Egypt's first digital factoring platform for medical claims

Cairo, Egypt – Nice Deer, a leading innovator in Egypt's health insurance technology (InsurTech) sector, proudly announces it has received official approval from the Financial Regulatory Authority (FRA) to establish Nice Deer for Financial Solutions Egypt's first fully digital non-banking financial institution (NBFI) dedicated to providing factoring services for deferred medical insurance claims. This regulatory milestone enables Nice Deer to offer real-time, structured financing to medical service providers, converting delayed insurance receivables into immediate cash. The goal is to directly address one of the most pressing challenges in the healthcare ecosystem: liquidity shortages due to delayed claim settlements. 'This license is more than just an operational milestone,' said Engy Shalash, Co-founder and Chief Marketing Officer of Nice Deer. 'It's a pivotal step toward creating a more agile and efficient model within the health insurance system. We're not just financing, we're resetting the market's tempo in favor of every provider who has long waited for their dues. Smart financing builds a faster, fairer economic cycle for the entire ecosystem.' With Egypt's medical insurance market valued at over EGP 300 billion annually, Nice Deer aims to factor EGP 500 million in medical claims within the first two years of operations. Delayed payments from insurance companies and Third-Party Administrators (TPAs) continue to place a heavy financial burden on healthcare providers. This often prevents providers from joining insurance networks, affects service quality, and contributes to low insurance penetration across the country. Nice Deer's digital factoring platform solves this problem by offering instant liquidity, backed by its proprietary AI-powered credit scoring engine, which analyzes real-time claims data, medical approvals, and utilization patterns. 'Financing is no longer a secondary option in the health insurance ecosystem; it's a strategic necessity,' said Mostafa Medhat Hussien, CEO of Nice Deer. 'Providers have long suffered from the time gap between service delivery and revenue collection, often forcing them to treat insurance patients differently from cash patients. Our platform uses integrated AI intelligence to assess risk with precision, streamline factoring decisions, and deliver a scalable, secure financial model, laying the foundation for a value-based healthcare system that prioritizes both better patient outcomes and provider sustainability.' Nice Deer's mission goes beyond simply offering financial liquidity. The company is actively building a new financial infrastructure for Egypt's healthcare sector, one designed to address longstanding inefficiencies and enable long-term sustainability. Through its digital platform, Nice Deer aims to improve cash flow for medical service providers, expand insurance penetration nationwide, and convert delayed, credit-based transactions into immediate cash settlements. By doing so, it seeks to encourage broader provider participation in payer networks and support the development of a more resilient, value-based healthcare ecosystem powered by smart, data-driven financial tools.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store