SoatDev IT Consulting
SoatDev IT Consulting
  • About us
  • Expertise
  • Services
  • How it works
  • Contact Us
  • News
  • August 12, 2023
  • Rss Fetcher

Trellix, a cybersecurity firm pioneering XDR, reveals Q2 2023 cyber threat insights in South Africa. The data underscores that government organizations remain the primary targets for threat actors seeking to breach South African IT systems.
In its recent threat report presented at the Trellix Cyberthreat Intelligence Briefing for South Africa, it was revealed that government systems faced 26% of all detected threat activity. Business service providers followed at 16%, with wholesalers’ networks at 14%, and utilities’ systems at 12%. Interestingly, the majority of threat activity surged on Mondays and Fridays.
Carlo Bolzonello, Trellix South Africa’s country lead, highlights, “Despite not experiencing a significant surge in detections since the first quarter, we have noticed a worrisome trend of specialized, well-equipped, and highly skilled threat actors. What’s even more alarming is their interconnection with extensive networks and potential state support, indicating a coordinated and sophisticated approach to their malicious activities.”
Trellix’s data further reveals that the Lazarus Group and Daggerfly Advanced Persistent Threats (APT) Group have intensified their targeted efforts to infiltrate critical South African systems.
The Lazarus Group, historically linked to a North Korean state-sponsored APT syndicate, initially operated as a criminal group. It has since been tied to the North Korean government by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). Lazarus deploys diverse tools like DDoS botnets, keyloggers, RATs, and wiper malware within broader HIDDEN COBRA operations.
Lazarus spear-phishes for credentials, and financial data, and uses “living off the land” tactics with fileless malware and legitimate tools.
Conversely, Daggerfly APT, possibly linked to China, intensifies its focus on African telecoms, raising concern. This threat actor focuses on information gathering, using methods like PlugX loaders and living off-the-land tooling.
Bolzonello underscores the destructive capabilities of some threat actor tools, pointing to their trail obfuscation techniques. He notes that adversaries skillfully manipulate time stamps and hide backdoors, making analysis exceedingly challenging for investigative teams.
He adds, “What is even more concerning is that these adversaries are highly proficient in evasion tactics, leaving organizations believing they have eliminated the threats, when in reality, they may still lie concealed.”
Trellix XDR detects, and mitigates advanced attacks, integrating seamlessly with third-party data sources through its native open architecture.
The platform analyzes 650+ security tools, offering actionable insights via Trellix Advance Research Centre for responsive security.

Previous Post
Next Post

Recent Posts

  • Sage Unveils AI Trust Label to Empower SMB’s
  • How African Startups Are Attracting Global Fintech Funding
  • After its data was wiped, KiranaPro’s co-founder cannot rule out an external hack
  • Meet the Finalists: VivaTech’s 5 Most Visionary Startups of 2025
  • Trump fast-tracks supersonic travel, amid spate of flight-related executive orders

Categories

  • Industry News
  • Programming
  • RSS Fetched Articles
  • Uncategorized

Archives

  • June 2025
  • May 2025
  • April 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023

Tap into the power of Microservices, MVC Architecture, Cloud, Containers, UML, and Scrum methodologies to bolster your project planning, execution, and application development processes.

Solutions

  • IT Consultation
  • Agile Transformation
  • Software Development
  • DevOps & CI/CD

Regions Covered

  • Montreal
  • New York
  • Paris
  • Mauritius
  • Abidjan
  • Dakar

Subscribe to Newsletter

Join our monthly newsletter subscribers to get the latest news and insights.

© Copyright 2023. All Rights Reserved by Soatdev IT Consulting Inc.