NCC warns Nigerians against banking app-targeting malware

The Nigerian Communications Commission has discovered a newly-hatched malicious software that steals users’ banking app login credentials on Android devices, the NCC spokesperson, Ikechukwu Adinde, disclosed in a statement on Sunday.
Discovered by the NCC’s Computer Security Incident Response Team, the malware steals credentials, combined with the use of SMS and notification interception to log in and use potential two-factor authentication tokens.
“A security advisory from the NCC CSIRT said the malicious software called ‘Xenomorph’, found to target 56 financial institutions across Europe, had a high impact and high vulnerability rate.
“Xenomorph is propagated by an application that was slipped into Google Play store and masquerading as a legitimate application called ‘Fast Cleaner’ ostensibly meant to clear junk, increase device speed and optimise the battery.
“Fast Cleaner was disseminated before the malware was placed on the remote server, making it hard for Google to determine that such an app is being used for malicious actions.
“This is to avoid early detection or being denied access to the Playstore,” he said.
He further explained that once up and running on a victim’s device, Xenomorph can harvest device information and SMS, intercept notifications and new SMS, perform overlay attacks and prevent users from uninstalling it.
“The threat also asks for Accessibility Services privileges, which allow it to grant itself further permissions.
“The Fast Cleaner app has now been removed from the Play Store but not before it garnered 50,000+ downloads,” he said.
Mr Adinde said that the commission had advised telecom consumers to be on alert in order not to fall victims of this manipulation.
He urged telecom consumers and other Internet users, particularly those using Android-powered devices, to use trusted Antivirus solutions and update them regularly to their latest definitions.
(NAN)
More from Peoples Gazette

Economy
Buhari regime will continue to borrow without subsidy removal: Femi Adesina
“You know how much could have been saved if the subsidy was removed and how it could have been diverted to other areas and spheres of national life.

Faith
Insecurity: Wake up to your responsibility, Cardinal Onaiyekan tells Buhari regime
The Catholic priest also appealed to Christians to pray in unity for progress, stability and peace to reign in Nigeria.

States
Ogun, Oyo, others to experience extended blackout: IBEDC
A statement issued by IBEDC’s spokesperson on Sunday said that Ogun, Oyo, Ibadan, Osun and Kwara States would be affected by the power outage.

Lagos
Fire: Lagos to train traders at Ladipo market
Lagos State Emergency Management Agency (LASEMA) disclosed this at a news conference on Sunday in Lagos.

Sport
Leeds sack Marcelo Bielsa
Club chairman Andrea Radrizzani said that sacking Bielsa was the “toughest decision” he has had to make.

Sport
Ukraine: France supports banning Russia from World Cup
Poland, Sweden and the Czech Republic have all refused to play Russia next month in the play-offs for the tournament in Qatar.

NationWide
Air Nigeria will start operations before Buhari leaves office: Official
The Minister of Aviation, Hadi Sirika, had announced April 2022 as the effective date for the take-off of the national carrier.