- According to a recent report published by cybersecurity intelligence firm, Recorded Future, Kenyan government entities were among those targeted by alleged Chinese hackers, RedJulliett, a report said.
- The cyber attacks from the group were spotted between November 2023 and April 2024, the report said. More than 24 government agencies from various nations, including Kenya and Rwanda, were attacked.
- They targeted organisations in government, education, technology, and diplomacy. Aside from government agencies, RedJulliet attacked websites belonging to religious organisations in Hong Kong and South Korea. A university in the United States and in Djibouti we’re also attacked.
The attacked servers were accessed through a vulnerability in their SoftEther enterprise virtual private network (VPN) software, used for remote connections to an organisation’s networks. Also, it leveraged structured query language (SQL) injection and directory traversal exploits against web and SQL applications.
While it is still unclear if the suspected group finally broke into those organisations, Recorded Future only observed the attempts to identify vulnerabilities in their networks.
For Kenya, this is not the first of its kind from Chinese hackers. Reuters reported in May 2023, that Chinese hackers targeted Kenya’s government including the finance ministry, the president’s office, spy agency in attempt to gain information on debt the country owes China.
In July of the same year, a Sudanese hacker group known as “Anonymous Sudan” reportedly hacked into Kenya’s eCitizen platform including NTSA, and disrupted its operations using a distributed denial-of-service (DDoS) attack. Moreover, the group’s action was claimed to be in response to Kenya’s supposed interference in Sudanese affairs.
But, Kenya may be getting help in cybersecurity in view of commitments from some tech companies. In May 2024, tech giants like Google and Microsoft in addition to making commitments for digital investments in the country, said they will provide joint effort and support in areas including cybersecurity.
Source
techpoint.africa