close
Monday, May 16, 2022

NCC uncovers hackers’ new ploy to unlock, steal vehicles in Nigeria

The NCC advised car owners in these categories to choose Passive Keyless Entry (PKE) as opposed to Remote Keyless Entry (RKE).

• May 15, 2022
Carjacking
Carjacking used to illustrate the story [Photo Credit: Sydney Criminal Lawyer]

The Nigerian Communications Commission (NCC) has alerted telecom consumers and public members on an ongoing cyber-vulnerability that allows a nearby hacker to unlock vehicles, start their engines wirelessly, and make away with them.

This is contained in the latest advisory released by the Computer Security Incident Response Team (CSIRT) established by the NCC and shared by the commission’s spokesperson, Ikechukwu Adinde.

“The fact that car remotes were categorised as short-range devices that use Radio Frequency (RF) to lock and unlock cars informed the need to alert Nigerians on this emergent danger.

“The vulnerability is a Man-in-the-Middle (MitM) attack or, more specifically, a replay attack in which an attacker intercepts the RF signals normally sent from a remote key fob to the car.

“It manipulates these signals and resends them later to unlock the car at will,” it stated.

The advisory stated that the latest cyber-attack gives room for easy manipulation of captured commands and re-transmitting them to achieve a different outcome altogether.

The commission’s spokesperson, however, said that the NCC-CSIRT, in the advisory, had offered some preventive measures or solutions that car owners could adopt to prevent falling victim.

According to the cyber-alert unit of the commission, when affected, the only mitigation is to reset your key fob at the dealership.

“Additionally, vulnerable car users should store their key fobs in signal-blocking ‘Faraday pouches’ when not in use.”

He advised car owners in these categories to choose Passive Keyless Entry (PKE) as opposed to Remote Keyless Entry (RKE), which would make it harder for an attacker to read the signal because criminals would need to be at close range to carry out their nefarious acts.

In a related advisory, he said that the NCC, based on another detection by CSIRT, wishes to inform the general public about the resurgence of Joker Trojan-Infected Android Apps on the Google Play Store.

“This arose due to the activities of criminals who intentionally download legitimate apps from the Play Store, modify them by embedding the Trojan malware and then upload the app back to the Play Store with a new name.

“The malicious payload is only activated once the apps go live on the Play Store, enabling the apps to scale through Google’s strict evaluation process.”

According to the advisory, the apps request for permissions and once granted, have access to critical functions.

“As a consequence, a compromised device will subscribe unwitting users to premium services, billing them for services that do not exist. A device like this can also be used to commit Short Messaging Service (SMS) fraud while the owner is unaware,” he said.

Mr Adinde said that the app could click on online ads automatically and even use SMS One-Time Password (OTPs) to approve payments without checking bank statements secretly.

The NCC also advised telecom consumers to ensure that apps installed from the Google Play Store are heavily scrutinised by reading reviews, assessing the developers, perusing the terms of use and only granting the necessary permissions.

(NAN) 

We have recently deactivated our website's comment provider in favour of other channels of distribution and commentary. We encourage you to join the conversation on our stories via our Facebook, Twitter and other social media pages.

More from Peoples Gazette

Politics

Emefiele’s Presidential Ambition: PDP thrives on nagging, says group

“We are aghast that a party like the PDP …. is the one tagging the Buhari government and Emefiele as corrupt.”

APC/Abdullahi Adamu

Politics

Ebonyi aspirants accuse APC leaders of fraud, intimidation

“We are told that we have to pay N200,000 as internally generated revenue; N200,000 for local government clearance and another N500,000 for state clearance.”

Orlando Julius (Credit: Nigerian Guardian)

Showbiz

Orlando Julius to be buried May 28

Nigerian Saxophonist, Julius Ekemode, popularly known as Orlando Julius, who died April 14, at the age of 79, would be laid to rest May 28 in his hometown, Ijebu Ijesha.

AU peacekeepers in Somalia

Africa

G5: Mali to quit Sahel military alliance

Mali on Sunday said it was leaving a five-country military alliance in the Sahel region of Africa.

Africa

Ex-Somali president re-elected as head of state

Former Somali President Hassan Sheikh Mohamud was on Sunday re-elected as head of state of the East African country.

California shooting scene (Credit: AP News)

Faith

Multiple people shot at California church

Multiple people were shot Sunday at a church in Laguna Woods in California’s Orange County, prompting a major response from Orange County Sheriff’s officials