Connect with us

Headline

NCC Discovers New Ways Hackers Steal Banking Details From Phone, Warns Nigerians

Published

on

The Nigerian Communications Commission’s Computer Security Incident Response Team (CSIRT) has discovered a newly-hatched malicious software that steals users’ banking app login credentials on Android devices.

According to a security advisory from the NCC CSIRT, the malicious software called “Xenomorph”, found to target 56 financial institutions from Europe, has high impact and high vulnerability rate.

The main intent of this malware is to steal credentials, combined with the use of SMS and Notification interception to log-in and use potential 2-factor authentication tokens.

Advertisement

Xenomorph is propagated by an application that was slipped into Google Play store and masquerading as a legitimate application called “Fast Cleaner” ostensibly meant to clear junk, increase device speed and optimize battery. In reality, this app is only a means by which the Xenomorph Trojan could be propagated easily and efficiently.

To avoid early detection or being denied access to the PlayStore, “Fast Cleaner” was disseminated before the malware was placed on the remote server, making it hard for Google to determine that such an app is being used for malicious actions.

Once up and running on a victim’s device, Xenomorph can harvest device information and Short Messaging Service (SMS), intercept notifications and new SMS messages, perform overlay attacks, and prevent users from uninstalling it. The threat also asks for Accessibility Services privileges, which allow it to grant itself further permissions.

Advertisement

READ ALSO: NCC Alerts Nigerians On Flubot Malware, Lists Measures To Guard Against Attack

The CSIRT said the malware also steals victims’ banking credentials by overlaying fake login pages on top of legitimate ones. Considering that it can also intercept messages and notifications, it allows its operators to bypass SMS-based two-factor authentication and log into the victims’ accounts without alerting them.

“Xenomorph has been found to target 56 internet banking apps, 28 from Spain, 12 from Italy, 9 from Belgium, and 7 from Portugal, as well as Cryptocurrency wallets and general-purpose applications like emailing services.

Advertisement

“The Fast Cleaner app has now been removed from the Play Store but not before it garnered 50,000+ downloads,” the CSIRT security advisory asserted.

“The Nigerian Communications Commission hereby wishes to advise telecom consumers to be on alert in order not to fall victim to this manipulation.

Accordingly, the NCC urges telecom consumers and other Internet users, particularly those using Android-powered devices to use trusted Antivirus solutions and update them regularly to their latest definitions.

Advertisement

The Commission also implored consumers and other stakeholders to always update banking applications to their most recent versions.

Advertisement
Comments

Headline

Russia Insists Ukraine Must Cede Land Or Face Continued Military Push

Published

on

Russian President Vladimir Putin said Thursday that he would end his Ukraine offensive if Kyiv withdrew from territory Moscow claims at its own — otherwise his army would take it by force.

The Russian army has been slowly but steadily grinding through eastern Ukraine in costly battles against outnumbered and outgunned Ukrainian forces.

Washington has meanwhile renewed its push to end the nearly four-year war, putting forward a surprise plan that it hopes to finalise through upcoming talks with Moscow and Kyiv.

Advertisement

“If Ukrainian forces leave the territories they hold, then we will stop combat operations,” Putin said during a visit to Kyrgyzstan. “If they don’t, then we will achieve it by military means.”

Russia controls around one-fifth of Ukraine’s territory. The issue of occupied land, which Kyiv has said it will never cede, is among the biggest stumbling blocks in the peace process.

READ ALSO:Putin Admits Russia Caused Azerbaijani Plane Crash

Advertisement

Another important issue in the talks are Western security guarantees for Ukraine, which Kyiv says are needed to prevent Moscow from invading again in the future.

Washington’s original plan — drafted without input from Ukraine’s European allies — would have seen Kyiv withdraw from its eastern Donetsk region and the United States de facto recognise the Donetsk, Crimea and Lugansk regions as Russian.

The US pared back the original plan over the weekend following criticism from Kyiv and Europe, but has not yet released the new version.

Advertisement

Putin, who has seen the new plan, said it could be a negotiation starter.

Overall, we agree that it could form the basis for future agreements,” he said of the latest draft, which the US is thought to have shortened to about 20 points.

READ ALSO:Russian Strikes Kill Five In Ukraine, Cause Power Outages

Advertisement

US negotiator Steve Witkoff was expected in Moscow next week to discuss the revised document, Putin said.

US Army Secretary Dan Driscoll is meanwhile due to visit Kyiv later this week, Ukraine’s top presidential aide Andriy Yermak said.

– ‘Little can be done’ –

Advertisement

In his remarks Thursday, Putin repeated the claim that Russia had encircled the Ukrainian army in Pokrovsk and Myrnograd in Ukraine’s eastern Donetsk region — the most fiercely embattled area and a key target for Moscow’s forces.

“Krasnoarmeysk and Dimitrov are completely surrounded,” he said, using the Russian names for the cities.

Moscow was also advancing in Vovchansk and Siversk, as well as approaching the important logistic hub of Guliaipole, he added.

Advertisement

The Russian offensive “is practically impossible to hold back, so there is little that can be done about it”, Putin said.

READ ALSO:Trump Urged Ukraine To Give Up Land In Peace Deal Talks — Official

Ukraine has denied Pokrovsk and Myrnograd are encircled, insisting its forces continue to hold the enemy along the front line.

Advertisement

Putin also questioned Ukrainian President Volodymyr Zelensky’s legitimacy and said signing any agreement with him would be legally “almost impossible” at the moment, a suggestion that has drawn groans from Kyiv and its allies.

According to data analysed by AFP from the American Institute for the Study of War (ISW), Russian forces have conquered an average of 467 square kilometres (180 square miles) each month in 2025 — a step up from 2024.

Moscow launched its full-scale invasion of Ukraine in February 2022, triggering the worst armed conflict in Europe since World War II.

Advertisement

The war has killed hundreds of thousands of people and forced millions to flee their homes.

Continue Reading

Headline

Morocco Jails French Rapper Maes For Kidnapping Bid

Published

on

A Moroccan court has sentenced French rapper Maes to seven years in prison on charges including the formation of a criminal gang and attempted kidnapping, local reports said Wednesday.

Maes, who has roots in Morocco and whose real name is Walid Georgey, was arrested upon landing in Morocco in January after fleeing the United Arab Emirates, where he feared he could be extradited to France, the reports said.

French authorities had issued an international arrest warrant for him over a separate criminal case.

Advertisement

He appeared in court late Tuesday and was found guilty of “forming a criminal organisation, attempted abduction and unlawful confinement” of a rival in Morocco, news website TelQuel reported.

READ ALSO:Bandits Claim Kebbi, Niger Abductions, Vow More Attacks On Soldiers, Politicians [VIDEO]

The rapper with over a billion views on his YouTube channel was accused of tasking a gang and hitmen with killing the rival, but the plot was foiled, TelQuel added.

Advertisement

Maes has denied all charges, with his lawyers calling the case “empty” and “arguing that no evidence linked him to the other defendants”, TelQuel added.

Ten other people were sentenced as part of the case, with terms ranging from one to 10 years, according to news website Media24.

AFP was unable to independently verify the reports as prosecutors were not immediately reachable for comment.

Advertisement

READ ALSO:Gov Mohammed Flags Off Construction Of 203.47-kilometre Rural Roads

In 2020, when Maes was one of France’s most-streamed rappers, he fell victim to extortion attempts in his native Sevran, a suburb north of Paris, according to reports.

He retaliated by opening fire with weapons he had at home, leading to a shootout. He then fled to Dubai with his family, according to an interview with French YouTube channel LEGEND.

Advertisement

Following the killing of his manager in 2022, he was suspected of ordering reprisals against those he believed were behind the murder, according to reports.

AFP

Advertisement
Continue Reading

Headline

UK Court Clears Comedy Writer Of Harassing Transgender Woman

Published

on

A London court on Tuesday cleared Emmy award-winning comedy writer Graham Linehan of harassing a transgender activist online but found him guilty of criminal damage to their mobile phone.

Linehan, who co-created the popular 1990s sitcom “Father Ted” but has more recently become well-known for his gender critical views, had been accused of sending Sophia Brooks “abusive and vindictive” messages on social media.

He was also charged with criminal damage after deliberately knocking a phone out of Brooks’s hand as they filmed him on the sidelines of a London conference.

Advertisement

Ruling on the case, District Judge Briony Clarke said she was not convinced Linehan’s conduct “was oppressive and unacceptable beyond merely unattractive, annoying or irritating”.

READ ALSO:UK Rejects Nigeria’s Request To Transfer Ekweremadu

Clarke also concluded Brooks was not “as alarmed and distressed as they portrayed themself to be”.

Advertisement

But convicting Linehan of criminal damage, the judge ruled he was “angry and fed up” and did not use “reasonable force” when the phone was taken from Brooks.

Clarke fined him £500 ($655) and ordered him to pay costs of £650 and a statutory surcharge of £200.

READ ALSO:Tinubu Appoints Non-Career Ambassadors For US, UK, France

Advertisement

The Irish writer, who also co-created the popular sitcoms “Black Books” and “The IT Crowd”, became embroiled in a free speech row in Britain earlier this year over his anti-transgender stance.

It followed his arrest at London’s Heathrow Airport by armed police over accusations of inciting violence with his X posts insulting transgender people.

The arrest sparked a backlash and claims of state overreach, including from US tech billionaire Elon Musk. But in October, UK prosecutors said they would take “no further action” in that case.

Advertisement

AFP

Continue Reading

Trending