Select your Top Menu from wp menus
  • Instagram
  • TikTok
Nam cybersecurity team highlights growing cybersecurity threats, calls for more vigilance

Nam cybersecurity team highlights growing cybersecurity threats, calls for more vigilance

Staff Reporter

The Namibia Cyber Security Incident Response Team (NAM-CSIRT), housed at the Communications Regulatory Authority of Namibia (CRAN), has released its fourth quarterly cybersecurity report for 2025, providing insights into the evolving cyber threat landscape and reinforcing the country’s commitment to protecting critical information infrastructure.

The protection of Namibia’s Critical Infrastructure (CI) and Critical Information Infrastructure (CII) remains a strategic national priority. As reliance on interconnected digital systems continues to grow, so does exposure to cyber threats.

During the period October to December 2025, NAM-CSIRT detected a total of 535,204 cyber vulnerabilities across various domains and IP addresses within the Namibian cyber landscape. This represents a 4.28% decrease compared to the previous quarter (July to September 2025). The top ten vulnerabilities identified primarily relate to misconfigured or outdated services, highlighting the importance of proper system maintenance and security updates.

Additionally, a total of 195,661 cyber events were recorded during the same period, reflecting a 50.94% decrease compared to the previous quarter. The data indicates a continued reduction in non-HTTP sinkhole activity, which declined from 243,446 in the previous quarter to 139,349. While this trend suggests improvement, the number of detections remains relatively high.

Despite these improvements, Namibia’s cyber landscape experienced an increase in phishing scams and continued cases of cyber-enabled fraud. These incidents often exploit weaknesses in public trust and organisational cyber hygiene, leading to financial losses and operational disruptions.

According to Emilia Nghikembua, Head of NAM-CSIRT, “incidents affecting CII have the potential to disrupt essential services, cause financial losses, undermine public confidence, and negatively impact economic activity.” She said that the report reflects both the progress made in strengthening Namibia’s cyber resilience and the need for continued vigilance in safeguarding the country’s cyberspace.

NAM-CSIRT defines Critical Information Infrastructure as computer systems and networks that are essential for national security and the economic and social well-being of citizens. Security incidents affecting such infrastructure can significantly disrupt essential services and economic operations.

In addition, the report highlights the emergence of new ransomware threat actors operating within the global cybercrime ecosystem. One such group, Genesis, was first observed in October 2025 and has rapidly gained traction.

The group relies on widely used ransomware techniques, including strong encryption mechanisms, the disruption or deletion of backup systems, and the use of native system utilities to enable lateral movement while evading detection. Genesis has drawn attention for its targeted attacks, particularly against organisations in the United States that manage sensitive or regulated data.

Another emerging ransomware operation identified in late 2025 is Benzona, which demonstrates a rapidly maturing operational capability. The group operates under a double-extortion model, encrypting victim systems while simultaneously exfiltrating sensitive data to pressure organisations into paying a ransom. The Windows-based ransomware encrypts files and appends a “benzona” extension, while deploying a ransom note titled RECOVERY_INFO.txt.

Victims are instructed to initiate communication through a Tor-based negotiation portal within 72 hours, with threats of public data disclosure if the demand is not met.

Moreover, the report also notes the growing prevalence of fraudulent websites designed to impersonate legitimate organisations. Cybercriminals are becoming increasingly sophisticated in creating spoofed websites that closely resemble authentic platforms to mislead users.

Beyond monitoring and incident response, NAM-CSIRT continues to strengthen regional cooperation and capacity building. In November 2025, the team participated in the Southern African Development Community (SADC) Cyber Drill and AfricaCERT meeting held in the Kingdom of Lesotho from 4 to 7 November 2025. The exercise forms part of ongoing efforts to operationalise the framework for establishing the SADC Regional Computer Incident Response Team (SR-CIRT) and to enhance member states’ capabilities in responding to cybersecurity incidents.

Picture for illustrative purposes only. Photo: NAM-CSIRT

Related posts