fbpx
Founder Institute Lagos Founder Institute Lagos Founder Institute Lagos
  • Home
  • About
  • Partners
  • Advertise
  • Contact
  • Signup to receive updates
Innovation | Startups | Funding | Tech Blog in Africa
Advertisement
  • Home
  • Startups
  • Hubs
  • Funding
  • WomenTech
  • CleanTech
  • Blockchain
No Result
View All Result
  • Home
  • Startups
  • Hubs
  • Funding
  • WomenTech
  • CleanTech
  • Blockchain
No Result
View All Result
Innovation | Startups | Funding | Tech Blog in Africa
No Result
View All Result
Home General

NCC-CSIRT advises Factory-Resetting Infected Devices to beat Xenomorph Malware

by Wale Oguntokun
2022/12/08
in General
Xenomorph
Share on FacebookShare on Twitter
Tweet
Share
Share

A malware, XENOMORPH, that installs Trojan in banking apps on the Android platform to steal login details, raid bank accounts, and read the users SMS, has been flagged by the Nigerian Communications Commission’s Computer Security Incident Response Team (NCC-CSIRT).

The Team suggests that owners of compromised devices take the extreme measure of doing factory resetting of infected devices.

NCC-CSIRT, citing Zscaler ThreatLabz, said, “The Todo: Day Manager hijacks your login info from banking apps, and can even read your SMS messages. It installs a banking trojan malware called Xenomorph that allows the app to intercept your two-factor verification codes (typically delivered over text) to raid your logins – and bank
account.

“Xenomorph performs overlay attacks by exploiting accessibility permissions in Android, resulting in the overlaying of fraudulent login screens on banking apps aimed at exfiltrating credentials.

RelatedPosts

WhiteBIT expands Operations to Nigeria, Allowing Local Crypto Traders Access to Global Market

InTouch, GTP partner to democratise Card Credentials Access for Unlocking Financial Inclusion in Africa

Fawry, Infobip partner to drive Electronic Payment Services

Improving Business Growth with Data Analytics: Why it’s a Priority

The Android app makes itself intentionally difficult to delete. You need to search your phone for it immediately and uninstall it.”

“It starts with asking users to enable access permission. Once provided, it adds itself as a device admin and prevents users from disabling Device Admin, making it un-installable from the phone.

If you haven’t given permission to the app, then you should be able to uninstall it safely. Otherwise, you may have to back up your files and then factory-reset your phone to clear the app completely,” it advised.

In terms of potential solutions to the malware, NCC-CSIRT advised that “Search your phone for the app and uninstall immediately or backup your files and factory reset your phone.

“Only search for an app in the Google Play Store, pay close attention to the search results, look at the apps icons, note that fake apps almost always use the icon from the app they’re faking, then look at the developer’s name and make sure it’s from the right developer.

Also, look at the app’s download count. If the app has a lot of downloads going into millions to hundreds of thousand that’s a clue that it’s the right app.

Then, finally, look at the app’s description and screenshots to ensure that it doesn’t contain multiple spelling or grammar mistakes or otherwise broken English.

“Make use of Google Play Protect, which regularly scans your apps for malware and will alert you to uninstall rogue apps.”

The CSIRT is the telecom sector’s cyber security incidence centre set up by the NCC to focus on incidents in the telecom sector and as they may affect telecom consumers and citizens at large.

The CSIRT also works collaboratively with Nigeria Cybersecurity Emergency Response Team (ngCERT), established by the Federal Government to reduce the volume of future computer risk incidents by preparing, protecting, and securing Nigerian cyberspace to forestall attacks, and problems or related events.


Don’t miss important articles during the week. Subscribe to techbuild.africa weekly digest for updates.

Join @techbuildafrica on Telegram
Tweet
Share
Share
ShareTweetShareSendShare

Subscribe us

Recent Posts

  • WhiteBIT expands Operations to Nigeria, Allowing Local Crypto Traders Access to Global Market
  • Apply for the Bill & Melinda Gates Foundation Grand Challenges ($100k)
  • InTouch, GTP partner to democratise Card Credentials Access for Unlocking Financial Inclusion in Africa
  • Fawry, Infobip partner to drive Electronic Payment Services
  • Improving Business Growth with Data Analytics: Why it’s a Priority
  • Anambra State Government to introduce E-ID CARD for Civil Servants
  • Microsoft Direct Routing is the Next Rung on the Ladder of Digital Transformation
  • Last call for the Africa by IncubMe Program (June 15)
  • NCC Boss to receive National Productivity Order of Merit Award
  • Apply for Proptech Accelerator Program ($300k)
Innovation | Startups | Funding | Tech Blog in Africa

© 2013-2021 techbuild.africa. All Rights Reserved.

Navigate Site

  • About
  • Contact
  • WE-Forum
  • Privacy
  • Sitemap
  • Terms
  • Blockchain
  • CleanTech

Follow Us

No Result
View All Result
  • Home
  • Startups
  • Hubs
  • Funding
  • WomenTech
  • CleanTech
  • Blockchain

© 2013-2021 techbuild.africa. All Rights Reserved.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In