ADVERTISEMENT

Malware alert: NCC alert Nigerians of bank-details stealing app

The Computer Security Incident Response Team (CSIRT) of the NCC has discovered new-fashioned malicious software capable of lifting users’ banking app login details on Android devices.

Malware alert: NCC alert Nigerians of bank-details stealing app

According to CSIRT, the malicious software called “Xenomorph” has targeted apps of 56 financial institutions in Europe because of its high impact and high vulnerability rate. Records of Xenomorph’s targeted attacks toll at 28 in Spain, 12 in Italy, 9 in Belgium, and 7 in Portugal, including Cryptocurrency wallets and general-purpose applications such as email services.

The primary purpose of this malware is to steal financial credentials and to intercept SMS and Notification messages in order to sign in and use potential two-factor authentication tokens by overlapping fake login pages on top of legitimate ones, enabling hackers to bypass “SMS-based two-factor authentication” and access ‘victims’ accounts without alerting them.

In a statement, NCC said,

“Xenomorph is propagated by an application that was slipped into Google Play store and masquerading as a legitimate application called ‘Fast Cleaner’ ostensibly meant to clear junk, increase device speed and optimize the battery.”

ADVERTISEMENT

“In reality, this app is only a means by which the Xenomorph Trojan could be propagated easily and efficiently. To avoid early detection or being denied access to the PlayStore, ‘Fast Cleaner’ was disseminated before the malware was placed on the remote server, making it hard for Google to determine that such an app is being used for malicious actions.”

“Once up and running on a victim’s device, Xenomorph can harvest device information and Short Messaging Service, intercept notifications and new SMS messages, perform overlay attacks, and prevent users from uninstalling it. The threat also asks for Accessibility Services privileges, which allow it to grant itself further permissions.”

As per CSIRT’s report, Fast Cleaner gained over 50,000 downloads despite being removed from Google Play Store.

Enhance Your Pulse News Experience!

Get rewards worth up to $20 when selected to participate in our exclusive focus group. Your input will help us to make informed decisions that align with your needs and preferences.

I've got feedback!

JOIN OUR PULSE COMMUNITY!

Unblock notifications in browser settings.
ADVERTISEMENT

Eyewitness? Submit your stories now via social or:

Email: eyewitness@pulse.ng

Recommended articles

Adelabu says FG plans to increase power generation from 4k to 6k megawatts

Adelabu says FG plans to increase power generation from 4k to 6k megawatts

Adeyanju denies appealing Bobrisky’s conviction

Adeyanju denies appealing Bobrisky’s conviction

FG shuts Abuja Chinese Supermarket that discriminates against Nigerians

FG shuts Abuja Chinese Supermarket that discriminates against Nigerians

Nigerian Army dismisses 2 soldiers who stole cable at Dangote Refinery

Nigerian Army dismisses 2 soldiers who stole cable at Dangote Refinery

1,802 suspects arrested in 2 weeks during Lagos raids

1,802 suspects arrested in 2 weeks during Lagos raids

Ribadu says terrorism-related deaths have dropped from 2600 monthly to 200

Ribadu says terrorism-related deaths have dropped from 2600 monthly to 200

Nigerian students under 18 shouldn't be in university — minister warns parents

Nigerian students under 18 shouldn't be in university — minister warns parents

End of controversy as Gov Adeleke names one of his wives as official First Lady

End of controversy as Gov Adeleke names one of his wives as official First Lady

Nigeria to boost collaboration, disrupt terrorism-fueling trafficking - Tinubu

Nigeria to boost collaboration, disrupt terrorism-fueling trafficking - Tinubu

ADVERTISEMENT
ADVERTISEMENT