Threat Intelligence
Francophone Africa.

Current threat landscape across 7 priority markets โ€” updated quarterly. Sources: national CERTs, FIRST network, public incident reports, INDEPTA field intelligence.

HIGH
MEDIUM-HIGH
MEDIUM
๐Ÿ‡ฒ๐Ÿ‡ฆ

Morocco

ma-cert.ma โ€” Operational
HIGH
DGSSIANRTBank Al-MaghribCNDP
Threat Summary

Most targeted country in North Africa. State-sponsored espionage + surging ransomware on financial sector. DGSSI actively tracking 12+ APT groups.

Active Threats
Ransomwareโ†‘ +67%LockBit 3.0, ALPHV
Phishing / BECโ†‘ +43%TA427 (Kimsuky)
Web Applicationโ†’ StableOpportunistic
DDoSโ†‘ +28%Hacktivists
Recent Incidents
Q1 2025 โ€” Wave of credential stuffing attacks against Moroccan banking apps
Q4 2024 โ€” DGSSI warns of APT campaign targeting Ministry of Digital
Q3 2024 โ€” Ransomware incident at regional hospital network, 48h service disruption
๐Ÿ‡ง๐Ÿ‡ซ

Burkina Faso

BURKINA-CERT โ€” Limited capacity
HIGH
ARCEP BFBCEAO
Threat Summary

Conflict environment elevates threat to CRITICAL for government. Disrupted civilian infrastructure. Foreign intelligence services active. Limited CERT capacity.

Active Threats
State-Sponsoredโ†‘ CriticalMultiple state actors
Ransomwareโ†‘ +74%Opportunistic
Infrastructure Sabotageโ†‘ ElevatedUnknown APT
Disinformationโ†‘ ElevatedState-linked
Recent Incidents
Q1 2025 โ€” Multiple government ministries report unauthorized access incidents
Q4 2024 โ€” Telecom infrastructure targeted amid broader conflict activity
๐Ÿ‡ฒ๐Ÿ‡ฑ

Mali

CERT-ML โ€” Limited capacity
HIGH
AMRTPBCEAO
Threat Summary

High-risk environment. Conflict-affected zones + political instability creates elevated cyber risk across all sectors. Limited national CERT capacity.

Active Threats
Ransomwareโ†‘ +61%Opportunistic + state
Telecommunications Disruptionโ†‘ ElevatedUnknown
Financial Fraudโ†‘ +38%Local + W.Africa groups
Infrastructureโ†‘ ElevatedState-linked
Recent Incidents
Q1 2025 โ€” Banking sector reports 61% increase in fraud attempts vs. prior year
Q4 2024 โ€” NGO sector targeted in multi-stage spear phishing campaign
๐Ÿ‡ธ๐Ÿ‡ณ

Senegal

CIRT Sรฉnรฉgal โ€” Operational
MEDIUM-HIGH
ARTPBCEAOCDP Sรฉnรฉgal
Threat Summary

Rapidly growing attack surface driven by digital finance adoption. BCEAO institutions primary target. Election-period hacktivism elevated.

Active Threats
Mobile Money Fraudโ†‘ +89%West Africa cybercrime groups
Ransomwareโ†‘ +41%LockBit, BianLian
Supply Chainโ†‘ +22%Unknown APT
Hacktivismโ†‘ ElevatedAnonymous Africa
Recent Incidents
Q1 2025 โ€” Wave of fake Wave/Orange Money apps distributing banking trojans
Q4 2024 โ€” Government portal defacement campaign during election period
Q3 2024 โ€” Telecoms operator suffers data exfiltration; 400K records exposed
๐Ÿ‡จ๐Ÿ‡ฎ

Cรดte d'Ivoire

FIRST member โ€” Active
MEDIUM-HIGH
ARTCIBCEAOAPDP
Threat Summary

Largest Francophone West African economy. BCEAO hub. High-value banking targets + expanding e-government surface. Sakawa fraud rings active.

Active Threats
Banking Trojansโ†‘ +52%West Africa cybercrime
CEO Fraud / BECโ†‘ +38%Sakawa operators
Ransomwareโ†‘ +29%LockBit, Akira
Insider Threatโ†’ StableInternal
Recent Incidents
Q1 2025 โ€” ARTCI warns of surge in deepfake-assisted social engineering targeting CFOs
Q4 2024 โ€” Payment processor hit by supply chain compromise via third-party vendor
Q2 2024 โ€” Mobile banking trojan "Abidjan Stealer" identified; 30K devices affected
๐Ÿ‡น๐Ÿ‡ณ

Tunisia

CERT Tunisie โ€” Operational
MEDIUM
ANSIBCTINPDP
Threat Summary

Most mature cyber ecosystem in North Africa outside Morocco. ANSI active. Exposed to North Africa APT campaigns and European-origin ransomware.

Active Threats
State Espionageโ†’ StableAPT34, Turla
Ransomwareโ†‘ +19%RansomHub, Play
DDoSโ†‘ +31%Pro-Russia hacktivists
Credential Theftโ†’ StableOpportunistic
Recent Incidents
Q1 2025 โ€” Series of DDoS attacks on government services linked to geopolitical tensions
Q3 2024 โ€” ANSI publishes national cybersecurity framework update
Q2 2024 โ€” Ransomware attack on logistics firm; BCT issues sector alert
๐Ÿ‡ง๐Ÿ‡ฏ

Benin

CERT-BJ โ€” Emerging
MEDIUM
ATRPTBCEAOCNDP Benin
Threat Summary

Stable governance, growing digital economy. BCEAO regulated banking sector primary target. E-government expansion increasing attack surface.

Active Threats
Mobile Fraudโ†‘ +44%West Africa groups
Phishingโ†‘ +29%Opportunistic
Ransomwareโ†‘ +18%LockBit affiliates
Web Defacementโ†’ StableScript kiddies
Recent Incidents
Q2 2025 โ€” BCEAO issues circular requiring PAM controls for all licensed banks
Q4 2024 โ€” Series of phishing campaigns targeting BCEAO-regulated institutions

Need a deeper threat briefing?

Ask ARIA โ€” INDEPTA's Africa Risk Intelligence Assistant.

Open ARIA โ†’