Top News

NCC-CSIRT advises Nigerians to factory-reset devices to beat xenomorph malware

A malware, Xenomorph, installs Trojan in banking apps on the Android platform to steal login details, raid bank accounts, and read the users’ SMS, has been flagged by the Nigerian Communications Commission’s Computer Security Incident Response Team (NCC-CSIRT).

The Team suggests that owners of compromised devices take the extreme measure of doing factory resetting of infected devices.

NCC-CSIRT, citing Zscaler ThreatLabz, said, “The Todo: Day Manager hijacks your login info from banking apps, and can even read your SMS messages. It installs a banking trojan malware called Xenomorph that allows the app to intercept your two-factor verification codes (typically delivered over text) to raid your logins – and bank account.

ALSO READ FROM NIGERIAN TRIBUNE 

“Xenomorph performs overlay attacks by exploiting accessibility permissions in Android, resulting in the overlaying of fraudulent login screens on banking apps aimed at exfiltrating credentials. The Android app makes itself intentionally difficult to delete. You need to search your phone for it immediately and uninstall it.”

“It starts with asking users to enable access permission. Once provided, it adds itself as a device admin and prevents users from disabling Device Admin, making it uninstallable from the phone. If you haven’t given permission to the app, then you should be able to uninstall it safely. Otherwise, you may have to back up your files and then factory-reset your phone to clear the app completely,” it advised.

In terms of potential solutions to the malware, NCC-CSIRT advised that “Search your phone for the app and uninstall immediately or backup your files and factory reset your phone.

“Only search for an app in the Google Play Store, pay close attention to the search results, look at the apps icons, note that fake apps almost always use the icon from the app they’re faking, then look at the developer’s name and make sure it’s from the right developer.

Also, NCC-CSIRT advise Nigerians to look at the app’s download count. “If the app has a lot of downloads going into millions to hundreds of thousand that’s a clue that it’s the right app. Then, finally, look at the app’s description and screenshots to ensure that it doesn’t contain multiple spelling or grammar mistakes or otherwise broken English”.

“Make use of Google Play Protect, which regularly scans your apps for malware and will alert you to uninstall rogue apps.”

Collins Nnabuife

Recent Posts

How to prevent your Gmail account from being hacked — Google

In a recent attack, hackers sent fake legal notices that looked like they came from…

2 minutes ago

Nigeria first policy hailed as game changer for national development

“This visionary policy will have far-reaching impacts on the economic empowerment, which means Mr. President…

9 minutes ago

‘Modern-day appeasement’: Biden criticizes Trump’s stance on Ukraine

“I just don't understand how people think that if we allow a dictator,

24 minutes ago

ECOWAS takes steps to boost digital connectivity in West Africa

Olagunju, who represented the Commissioner for Infrastructure, Energy and Digitalisation, Mr. Sediko Douka, also said,…

30 minutes ago

EFCC: How celebrities, politicians reacted to VeryDarkMan’s arrest so far

Davido tweeted: “Outside all the noise it’s good to see that the good one does…

34 minutes ago

NEDC reaffirms commitment to rebuilding North-East economy

The North-East Development Commission (NEDC) has reaffirmed its commitment to rebuilding the economy of the…

50 minutes ago

Welcome

Install

This website uses cookies.