Rootkit detections in South Africa up by 74%

Issue 4 2023 News & Events, Information Security

As reported by Kaspersky, the number of rootkit detections targeting businesses in South Africa grew by 74% in the first five months of 2023. In Kenya, the figure is 52% and in Nigeria 139%.

A rootkit is a malicious software or a collection of software programs used by cybercriminals to snoop into a computer or network and gain administrator-level control. One of the most common methods used by cybercriminals to install rootkits is to compromise the supply chain of a specific victim.

The uniqueness of a rootkit lies in its considerable amount of stealth, which cybercriminals aptly use to conceal their presence while carrying out their malicious activity and bypass security controls. Often, rootkit detections are difficult to investigate and analyse. It’s highly evasive design enables cybercriminals to steal personal data, access financial information, install malware, and use computers as part of a botnet to circulate spam or launch DDoS attacks. Rootkit malware can remain on a computer for a very long time, causing significant damage.

“APT groups are the trendsetters of the cyberthreat landscape. They consider ‘stealth’ to be key for successful exploitative tactics because you cannot protect yourself from something you cannot see. A rootkit perfectly fits the type of technique they would use. As reported previously, some of the APT groups had started leveraging rootkits in their activities. This trend caught the attention of other APT groups, cybercriminals and hacker communities, creating a domino effect and resulting in an increased use of rootkits,” said Abdessabour Arous, Security Researcher, Global Research and Analysis Team at Kaspersky.

“Since a rootkit can be installed on any hardware or software platforms, it is becoming far more dangerous as IoT and cloud technologies create a well-connected and integrated environment.”

To protect governments and organisations against a rootkit, Kaspersky researchers recommend:

• Restrict access and establish strict security protocols for the use of admin privileges.

• Use the latest version of operating systems that can mitigate rootkit deployment.

• Ensure all security features of your operating systems are activated.

• Update your Unified Extensible Firmware Interface (UEFI) firmware regularly. Use software from trusted vendors only.

• Ensure you use robust cybersecurity solutions that can eliminate risks from your IT supply chain as third-party attacks are gaining momentum.

• Leverage services like the Kaspersky Threat Intelligence to leverage real-time insights on cyberthreat tactics, techniques, tools and methods.

• Having an incident response process and security monitoring capabilities in place is also helpful.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
From the editor's desk: Showtime for Securex
Technews Publishing News & Events
We have once again reached the time of year when the security industry focuses on Securex. This issue includes a short preview, with more coming online and via our special Securex Preview news briefs. ...

Read more...
Chubbsafes celebrates 190 years
Gunnebo Safe Storage Africa News & Events Security Services & Risk Management
Chubbsafes marks its 190th anniversary in 2025 and as a highlight of the anniversary celebrations it is launching the Chubbsafes 1835, a limited edition 190th-anniversary collector’s safe.

Read more...
Suprema unveils BioStar Air
Suprema neaMetrics News & Events Access Control & Identity Management Infrastructure
Suprema launches BioStar Air, the first cloud-based access control platform designed to natively support biometric authentication and feature true zero-on-premise architecture. BioStar Air simplifies deployment and scales effortlessly to secure SMBs, multi-branch companies, and mixed-use buildings.

Read more...
New law enforcement request portal
News & Events Security Services & Risk Management
inDrive launches law enforcement request portal in South Africa to support safety investigations. New portal allows authorised South African law enforcement officials to securely request user data related to safety incidents.

Read more...
Igniting standards, powering protection
Securex South Africa News & Events Fire & Safety
Fire safety is more than compliance, it is a critical commitment to protecting lives, assets, and infrastructure. At Firexpo 2025, taking place from 3 to 5 June at Gallagher Convention Centre, that commitment takes centre stage.

Read more...
Back-up securely and restore in seconds
Betatrac Telematic Solutions Editor's Choice Information Security Infrastructure
Betatrac has a solution that enables companies to back-up up to 8 TB of data onto a device and restore it in 30 seconds in an emergency, called Rapid Access Data Recovery (RADR).

Read more...
The rise of AI-powered cybercrime and defence
Information Security News & Events AI & Data Analytics
Check Point Software Technologies launched its inaugural AI Security Report, offering an in-depth exploration of how cybercriminals are weaponising artificial intelligence (AI), alongside strategic insights defenders need to stay ahead.

Read more...
From the editor's desk: We’ve only just begun
Technews Publishing News & Events
The surveillance market has expanded far beyond the analogue days of just recording and/or monitoring screens. The capabilities of surveillance technology today extend to black screen monitoring with ...

Read more...
SAFPS issues SAPS impersonation scam warning
News & Events Security Services & Risk Management
The Southern African Fraud Prevention Service (SAFPS) is warning the public against a scam in which scammers pose as members of the South African Police Service (SAPS) and trick and intimidate individuals into handing over personal and financial information.

Read more...