African Banks Under Siege: Hackers Turn Legitimate Tools Into Weapons for Million-Dollar Access Schemes


# African Financial Institutions Under Siege: New Cybercriminal Campaign Targets Banking Sector

Cybersecurity researchers have identified a sophisticated attack campaign targeting financial organizations across Africa since July 2023. The operation, designated CL-CRI-1014 by Palo Alto Networks Unit 42, represents a growing threat to the continent’s banking infrastructure.

## The Criminal Business Model

The attackers operate as initial access brokers (IABs), focusing on infiltrating networks and selling access credentials to other cybercriminals on underground forums. This business model has become increasingly popular among threat actors seeking to monetize their intrusion capabilities.

## Attack Methods and Tools

The cybercriminals employ a combination of legitimate and malicious tools to maintain stealth:

**Primary Tools:**
– **PoshC2**: Command-and-control framework
– **Chisel**: Network tunneling tool
– **Classroom Spy**: Remote administration software
– **MeshCentral Agent**: Remote access platform

**Deception Tactics:**
The attackers disguise their malicious payloads by copying signatures from legitimate applications and using recognizable icons from Microsoft Teams, Palo Alto Networks Cortex, and VMware Tools.

## Attack Progression

Once initial access is gained, the threat actors follow a systematic approach:

1. Deploy MeshCentral Agent for initial control
2. Install Classroom Spy for enhanced remote administration
3. Use Chisel to bypass firewall restrictions
4. Spread PoshC2 across the network to additional Windows systems

## Persistence Mechanisms

To maintain long-term access, the attackers establish persistence through multiple methods:
– Creating system services
– Placing startup shortcuts in Windows folders
– Setting up scheduled tasks disguised as “Palo Alto Cortex Services”

## Historical Context

This campaign follows previous attacks on African financial institutions. In 2022, the DangerousSavanna campaign targeted banks and insurance companies across Ivory Coast, Morocco, Cameroon, Senegal, and Togo using similar tools including PoshC2 and Metasploit.

## Emerging Threat: Dire Wolf Ransomware

Separately, security researchers have identified a new ransomware group called Dire Wolf, which has compromised 16 organizations globally since last month. The group primarily targets technology, manufacturing, and financial services sectors across multiple countries including the U.S., Thailand, Australia, and Canada.

**Dire Wolf Capabilities:**
– Written in Golang programming language
– Disables system logging
– Terminates 75 services and 59 applications
– Deletes shadow copies to prevent recovery

## Security Implications

These campaigns highlight the evolving threat landscape facing financial institutions, particularly in emerging markets. Organizations must implement comprehensive security measures including network monitoring, endpoint protection, and employee training to defend against these sophisticated attacks.

The rise of initial access brokers represents a concerning trend in cybercrime, as it lowers the barrier to entry for less skilled attackers while providing specialized intrusion teams with steady revenue streams.

Share This Article