x

NCC warns on new software that steals users’ banking app login credentials

The Nigerian Communications Commission’s Computer Security Incident Response Team, CSIRT, has warned Nigerians to be wary of a newly-hatched malicious software that steals users’ banking app login credentials on Android devices.

According to a security advisory from the NCC CSIRT, the malicious software, called “Xenomorph,” found to target 56 financial institutions in Europe, has high impact and high vulnerability rate.

NCC said the main intent of this malware was to steal credentials, combined with the use of SMS and notification interception to log-in and use potential 2-factor authentication tokens.

“Xenomorph is propagated by an application that was slipped into Google Play store and masquerading as a legitimate application called “Fast Cleaner” ostensibly meant to clear junk, increase device speed and optimize battery. In reality, this app is only a means by which the Xenomorph Trojan could be propagated easily and efficiently.

“To avoid early detection or being denied access to the PlayStore, ‘Fast Cleaner’ was disseminated before the malware was placed on the remote server, making it hard for Google to determine that such an app is being used for malicious actions.

“Once up and running on a victim’s device, Xenomorph can harvest device information and Short Messaging Service (SMS), intercept notifications and new SMS messages, perform overlay attacks, and prevent users from uninstalling it. The threat also asks for Accessibility Services privileges, which allow it to grant itself further permissions.

“The CSIRT said the malware also steals victims’ banking credentials by overlaying fake login pages on top of legitimate ones. Considering that it can also intercept messages and notifications, it allows its operators to bypass SMS-based two-factor authentication and log into the victims’ accounts without alerting them.”

Hot this week

Oil Firm Confirms Three Dead in Road Mishap in Akwa Ibom, Reaffirms Safety Measures

By Ogenyi Ogenyi, UyoThe management of Sterling Petrochemicals and...

Nasarawa Accountant General Resigns, Declares 2027 Governorship Bid

By Abel Zwanke, LafiaThe Accountant General of Nasarawa State,...

FG to Collaborate with AGFAN to Boost Economic Development

By Francis WilfredThe Federal Government has reiterated its readiness...

Jikwoyi Building Collapse Leaves One Traped, 8 Victims Hospitalised in Abuja

By Joyce Remi BabayejuA Jikwoyi building collapse which occured...

AIG Adenola Congratulates Newly Decorated Police Officers

Assistant Inspector General of Police, Zone 16, , has...

Easter: Orelope-Adefulire Urges Renewed Commitment to Sustainable Development

The Senior Special Assistant to the President on Sustainable...

PDP Chieftain, Onireti Resigns From Party, Cites Personal Reflection

A former House of Representatives candidate, Olufemi Onireti, has...

Kogi Governor Ododo Appoints Prof. M.S. Audu as Pro-Chancellor of PAAU Anyigba

The Governor of Kogi State, Ahmed Usman Ododo, has...

TCN Disputes PHEDC Capacity Claims, Cites Verified 8,700MW Transmission Capability

The Transmission Company of Nigeria (TCN) has challenged capacity...

CSOs Condemn Wike’s Remarks on Journalist, Raise Concerns Over Press Freedom

A coalition of 14 civil society organisations (CSOs) has...

Kogi Orders Evacuation of Students from University of Jos Over Security Concerns

Governor Ahmed Usman Ododo has directed the evacuation of...

Related Articles

Popular Categories

spot_imgspot_img