Connect with us

Headline

NCC Discovers New Ways Hackers Steal Banking Details From Phone, Warns Nigerians

Published

on

The Nigerian Communications Commission’s Computer Security Incident Response Team (CSIRT) has discovered a newly-hatched malicious software that steals users’ banking app login credentials on Android devices.

According to a security advisory from the NCC CSIRT, the malicious software called “Xenomorph”, found to target 56 financial institutions from Europe, has high impact and high vulnerability rate.

The main intent of this malware is to steal credentials, combined with the use of SMS and Notification interception to log-in and use potential 2-factor authentication tokens.

Advertisement

Xenomorph is propagated by an application that was slipped into Google Play store and masquerading as a legitimate application called “Fast Cleaner” ostensibly meant to clear junk, increase device speed and optimize battery. In reality, this app is only a means by which the Xenomorph Trojan could be propagated easily and efficiently.

To avoid early detection or being denied access to the PlayStore, “Fast Cleaner” was disseminated before the malware was placed on the remote server, making it hard for Google to determine that such an app is being used for malicious actions.

Once up and running on a victim’s device, Xenomorph can harvest device information and Short Messaging Service (SMS), intercept notifications and new SMS messages, perform overlay attacks, and prevent users from uninstalling it. The threat also asks for Accessibility Services privileges, which allow it to grant itself further permissions.

Advertisement

READ ALSO: NCC Alerts Nigerians On Flubot Malware, Lists Measures To Guard Against Attack

The CSIRT said the malware also steals victims’ banking credentials by overlaying fake login pages on top of legitimate ones. Considering that it can also intercept messages and notifications, it allows its operators to bypass SMS-based two-factor authentication and log into the victims’ accounts without alerting them.

“Xenomorph has been found to target 56 internet banking apps, 28 from Spain, 12 from Italy, 9 from Belgium, and 7 from Portugal, as well as Cryptocurrency wallets and general-purpose applications like emailing services.

Advertisement

“The Fast Cleaner app has now been removed from the Play Store but not before it garnered 50,000+ downloads,” the CSIRT security advisory asserted.

“The Nigerian Communications Commission hereby wishes to advise telecom consumers to be on alert in order not to fall victim to this manipulation.

Accordingly, the NCC urges telecom consumers and other Internet users, particularly those using Android-powered devices to use trusted Antivirus solutions and update them regularly to their latest definitions.

Advertisement

The Commission also implored consumers and other stakeholders to always update banking applications to their most recent versions.

Advertisement
Comments

Headline

UK Police Arrest Asylum Seeker Sex Offender Mistakenly Freed

Published

on

The UK police on Sunday arrested an Ethiopian asylum seeker and convicted sex offender, whose crimes had sparked anti-immigration protests, after he was accidentally released from prison in an embarrassing blunder by British authorities.

London’s Metropolitan Police said officers arrested Hadush Kebatu in the north of the capital on Sunday morning, nearly 48 hours after he was mistakenly freed around 30 miles (48 kilometres) away.

Kebatu, 38, had served the first month of a one-year sentence for sexually assaulting a teenage girl and a woman, but was reportedly due to be deported when the Prison Service error occurred on Friday.

Advertisement

His high-profile case earlier this year in Epping, northeast of London, sparked demonstrations in various English towns and cities where asylum seekers were believed to be housed, as well as counter-protests.

READ ALSO:UK Police Hunt Asylum Seeker Mistakenly Freed For Sex Offence

Commander James Conway, who oversaw the manhunt for him, said “information from the public” led officers to the Finsbury Park neighbourhood of London, where he was found.

Advertisement

He was detained by police but will be returned to the custody of the Prison Service,” he added.

Kebatu is now expected to be deported.

Prime Minister Keir Starmer said Friday he was “appalled” by the “totally unacceptable” mistake that saw him freed rather than sent to an immigration detention centre.

Advertisement

The Telegraph newspaper said he was wrongly categorised for release on licence and handed a £76 ($101) discharge grant.

READ ALSO:Alleged Misappropriation: MFM Accuses UK Agency Of Discrimination

Police had appealed Saturday for Kebatu to turn himself in, after reports emerged that he had appeared confused and reluctant to leave the prison in Chelmsford, eastern England.

Advertisement

A delivery driver described seeing Kebatu return several times in a “very confused” state, only to be turned away by staff and directed to the railway station.

The driver told Sky News he saw Kebatu outside the jail, asking, “Where am I going? What am I doing?”

He was starting to get upset, he was getting stressed,” the driver said.

Advertisement

READ ALSO:UK Is A Home, Not Hotel, Kemi Badenoch Tells Immigrants, Starmer’s Govt

The father of Kebatu’s anonymous teenage victim told the broadcaster that “the justice system has let us down.”

Police arrested the asylum seeker in July after he repeatedly tried to kiss a 14-year-old girl and touch her legs, and made sexually explicit comments to her.

Advertisement

He also sexually assaulted an adult woman, placing a hand on her thigh, when she intervened to stop his interactions with the girl.

He was staying at the time at Epping’s Bell Hotel, where scores of other asylum seekers have been accommodated, and which became the target of repeated protests.

AFP

Advertisement

 

Continue Reading

Headline

Madagascar Revokes Ousted President’s Nationality

Published

on

Madagascar’s new government has stripped ousted president Andry Rajoelina of his Malagasy nationality in a decree published Friday, 10 days after he was removed in a military takeover.

According to AFP, the decree means that Rajoelina, who was impeached on October 14 after fleeing the island nation in the wake of weeks of protests, would not be able to contest future election.

The decree published in the official gazette said Rajoelina’s Malagasy nationality was revoked because he had acquired French nationality in 2014, local media reported, as photographs of the document were shared online.

Advertisement

READ ALSO:Madagascar’s President Denounces ‘Coup Attempt’ As Gen Z Protests Escalate

French broadcaster RFI said it had confirmed the decree with the entourage of the new prime minister, Herintsalama Rajaonarivelo, who signed the order.

The decree cited laws stipulating that a Malagasy who voluntarily acquires a foreign nationality loses their Malagasy nationality.

Advertisement

Rajoelina’s French nationality caused a scandal when it was revealed ahead of the November 2023 elections, nearly 10 years after it was granted.

READ ALSO:Madagascar Passes Bill To Castrate Child R*pists

It triggered calls for him to be disqualified but he went on to win the contested polls, which were boycotted by opposition parties.

Advertisement

The 51-year-old politician fled Madagascar after army Colonel Michael Randrianirina said on October 11 his CAPSAT unit would refuse orders to put down the youth-led protest movement, which security forces had attempted to suppress with violence.

Rajoelina said later he was in hiding for his safety, but did not say where.

Randrianirina was sworn in as president on October 14, pledging elections within two years.

Advertisement
Continue Reading

Headline

Kamala Harris Hints At Running For President Again

Published

on

Former US vice president Kamala Harris said in a British television interview previewed in Saturday that she may “possibly” run again to be president.

Harris, who replaced Joe Biden as the 2024 Democratic presidential candidate but lost to Donald Trump, told the BBC that she had not yet decided whether to make another White House bid.

But the 61-year-old insisted she was “not done” in American politics and that her young grandnieces would see a female president in the Oval Office “in their lifetime, for sure”.

Advertisement

READ ALSO:FULL LIST: Trump, Kamala, Netanyahu, Others Shortlisted For 2024 Time’s Person Of The Year

“I have lived my entire career a life of service, and it’s in my bones, and there are many ways to serve.

“I’ve not decided yet what I will do in the future, beyond what I am doing right now,” Harris told the British broadcaster in an interview set to air in full on Sunday.

Advertisement

The comments are the strongest hint yet that Harris could attempt to be the Democratic Party nominee for the 2028 election.

READ ALSO:Kamala Harris Secures Democratic Presidential Nomination

The interview follows the release of her memoir last month, in which she argued it had been “recklessness” to let Biden run for a second term as president.

Advertisement

She also accused his White House team of failing to support her while she was his deputy, and at times of actively hindering her.

AFP

Advertisement
Continue Reading

Trending