close
Sunday, February 27, 2022

NCC warns Nigerians against banking app-targeting malware

Xenomorph can harvest device information and SMS, intercept notifications and new SMS, perform overlay attacks and prevent users from uninstalling it.

• February 27, 2022
Nigerian Communications Commission
Nigerian Communications Commission

The Nigerian Communications Commission has discovered a newly-hatched malicious software that steals users’ banking app login credentials on Android devices, the NCC spokesperson, Ikechukwu Adinde, disclosed in a statement on Sunday.

Discovered by the NCC’s Computer Security Incident Response Team, the malware steals credentials, combined with the use of SMS and notification interception to log in and use potential two-factor authentication tokens.

“A security advisory from the NCC CSIRT said the malicious software called ‘Xenomorph’, found to target 56 financial institutions across Europe, had a high impact and high vulnerability rate.

“Xenomorph is propagated by an application that was slipped into Google Play store and masquerading as a legitimate application called ‘Fast Cleaner’ ostensibly meant to clear junk, increase device speed and optimise the battery.

“Fast Cleaner was disseminated before the malware was placed on the remote server, making it hard for Google to determine that such an app is being used for malicious actions.

“This is to avoid early detection or being denied access to the Playstore,” he said.

He further explained that once up and running on a victim’s device, Xenomorph can harvest device information and SMS, intercept notifications and new SMS, perform overlay attacks and prevent users from uninstalling it.

“The threat also asks for Accessibility Services privileges, which allow it to grant itself further permissions.

“The Fast Cleaner app has now been removed from the Play Store but not before it garnered 50,000+ downloads,” he said.

Mr Adinde said that the commission had advised telecom consumers to be on alert in order not to fall victims of this manipulation.

He urged telecom consumers and other Internet users, particularly those using Android-powered devices, to use trusted Antivirus solutions and update them regularly to their latest definitions.

(NAN)

More from Peoples Gazette

Economy

Buhari regime will continue to borrow without subsidy removal: Femi Adesina

“You know how much could have been saved if the subsidy was removed and how it could have been diverted to other areas and spheres of national life.

Cardinal John Oniayekan (Credit: BBC)

Faith

Insecurity: Wake up to your responsibility, Cardinal Onaiyekan tells Buhari regime

The Catholic priest also appealed to Christians to pray in unity for progress, stability and peace to reign in Nigeria.

Lantern light and Powergrid used to illustrate the story

States

Ogun, Oyo, others to experience extended blackout: IBEDC

A statement issued by IBEDC’s spokesperson on Sunday said that Ogun, Oyo, Ibadan, Osun and Kwara States would be affected by the power outage.

Photo of Federal Fire Service used to illustrate this story

Lagos

Fire: Lagos to train traders at Ladipo market

Lagos State Emergency Management Agency (LASEMA) disclosed this at a news conference on Sunday in Lagos.

Sport

Leeds sack Marcelo Bielsa

Club chairman Andrea Radrizzani said that sacking Bielsa was the “toughest decision” he has had to make.

Sport

Ukraine: France supports banning Russia from World Cup

Poland, Sweden and the Czech Republic have all refused to play Russia next month in the play-offs for the tournament in Qatar.

Minister of aviation Hadi Sirika

NationWide

Air Nigeria will start operations before Buhari leaves office: Official

The Minister of Aviation, Hadi Sirika, had announced April 2022 as the effective date for the take-off of the national carrier.