logo

Cybercriminals Abuse Open-Source Tools To Target Africa’s Financial Sector

ID: da5006f6-17e8-543e-9f59-fa40c1ab3c4b

STIX ID: report--da5006f6-17e8-543e-9f59-fa40c1ab3c4b

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2025-06-24

Date Updated: 2026-04-28

Author: Tom Fakterman and Guy Levi

...
...

Unit 42 describes CL-CRI-1014, a cluster of activity targeting financial organizations in Africa that appears to act as an initial access broker: actors use publicly available tools (PoshC2, Chisel, Classroom Spy), packers, stolen signatures and evasion techniques to gain footholds, move laterally, establish persistence, and create tunnels/proxies for C2; the report includes technical analysis, examples of tactics and artifacts, and multiple IOCs (file hashes and domains) to aid detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.