Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors DangerousSavanna

Description

Malicious campaign called DangerousSavanna has been targeting multiple major financial service groups in French-speaking Africa for the last two years. The threat actors behind this campaign use spear-phishing as a means of initial infection, sending emails with malicious attachments to the employees of financial institutions in at least five different French-speaking countries: Ivory Coast, Morocco, Cameroon, Senegal, and Togo. DangerousSavanna tends to install relatively unsophisticated software tools in the infected environments. These tools are both self-written and based on open-source projects such as Metasploit, PoshC2, DWservice, and AsyncRAT. The threat actors’ creativity is on display in the initial infection stage, as they persistently pursue the employees of the targeted companies, constantly changing infection chains that utilize a wide range of malicious file types, from self-written executable loaders and malicious documents, to ISO, LNK, JAR and VBE files in various combinations. The evolving infection chains by the threat actor reflect the changes in the threat landscape seen over the past few years as infection vectors became more and more sophisticated and diverse.

AI Analysis

· 1 week ago

Executive Summary

DangerousSavanna is a cyber threat actor targeting financial institutions in French-speaking Africa through sophisticated phishing campaigns. Their primary method involves spear-phishing emails with malicious attachments, including various file types like ISO and LNK. They use open-source tools and self-written malware to compromise systems, aiming to disrupt or gain unauthorized access to sensitive financial data.

Goals & Targeting

DangerousSavanna's strategic objective appears to be gaining unauthorized access to financial institutions' systems in French-speaking African countries. Their targeting of sectors critical to national economies suggests a focus on economic gain or disruption. The choice of victims aligns with their operational capabilities and geographic reach, focusing on entities where successful compromise could yield significant financial or intelligence benefits.

Enhanced Description

DangerousSavanna is an active cyber threat actor focusing on financial institutions in French-speaking African countries such as Ivory Coast, Morocco, Cameroon, Senegal, and Togo. The group has been operational for at least two years, employing phishing emails with malicious attachments as their primary infection vector. Their campaigns are notable for the diversity of file types used, including self-written executable loaders, malicious documents, ISO, LNK, JAR, and VBE files. DangerousSavanna demonstrates adaptability by frequently updating their infection chains, reflecting the evolving threat landscape. The group's tools are a mix of open-source projects such as Metasploit, PoshC2, DWservice, and AsyncRAT, alongside self-developed software. Despite their relatively unsophisticated toolkit compared to other advanced persistent threats, their persistence and creativity in compromising targets make them a notable threat.

Key Capabilities

  • Spear-phishing campaigns
  • Diverse malicious file types
  • Use of open-source tools (Metasploit, PoshC2)
  • Self-written malware
  • Adaptive infection chains

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion
Discovery
Lateral Movement
Exfiltration

ATT&CK Techniques

T1059
T1059.003
T1567
T1053.PS2PowerShell
T1078
T1071
T1214

Software / Tooling

Metasploit
PoshC2
DWservice
AsyncRAT
Custom RAT

Campaigns & Victims

DangerousSavanna operates with a clear focus on financial services, leveraging phishing campaigns to penetrate targets. Their campaigns are characterized by continuous evolution of infection vectors, indicating adaptability to defensive measures. Past operations include multiple successful compromises in French-speaking Africa, targeting both public and private sector entities. Notably, their use of open-source tools suggests an effort to minimize detection while maintaining functional effectiveness.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Diverse file types (ISO, LNK, JAR, VBE)
  • Malicious scripts in document files
  • Signs of persistence via scheduled tasks

Recommended Actions

  • Implement advanced email filtering solutions to block spear-phishing attempts.
  • Educate employees on phishing tactics and suspicious emails.
  • Monitor network traffic for signs of unauthorized access or tool deployment.
  • Conduct regular endpoint scans for known malicious file types and scripts.
  • Adopt a Zero Trust model to limit lateral movement within networks.

Suggested Tags

APT
Ransomware
Financial-Sector
fraud

Confidence Assessment

Moderate confidence in DangerousSavanna's details exists, with clear descriptions of tactics and targets but limited information on specific financial motivations or long-term strategic goals. The group's operational methods are well-documented, but gaps remain regarding their exact origins, potential state affiliations, and whether they operate for monetary gain or broader disruption.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
Phishing
APT
Ransomware
Financial-Sector
fraud

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.