Connect with us

Headlines

NCC discovers software that steals banking app login credentials

Published

on

Nasiru Yusuf

The Nigerian Communications Commission’s Computer Security Incident Response Team (CSIRT) has discovered a newly-hatched malicious software that steals users’ banking app login credentials on Android devices.

KANO FOCUS reports that a security advisory from the NCC CSIRT, the malicious software called “Xenomorph”, found to target 56 financial institutions from Europe, has high impact and high vulnerability rate.

According to a statement issued by commission’s spokesperson Ikechukwu Adinde the main intent of this malware is to steal credentials, combined with the use of SMS and Notification interception to log-in and use potential 2-factor authentication tokens.

The statement added that the Xenomorph is propagated by an application that was slipped into Google Play store and masquerading as a legitimate application called “Fast Cleaner” ostensibly meant to clear junk, increase device speed and optimize battery. In reality, this app is only a means by which the Xenomorph Trojan could be propagated easily and efficiently.

It noted that to avoid early detection or being denied access to the PlayStore, “Fast Cleaner” was disseminated before the malware was placed on the remote server, making it hard for Google to determine that such an app is being used for malicious actions.

To this end the statement cautioned that once up and running on a victim’s device, Xenomorph can harvest device information and Short Messaging Service (SMS), intercept notifications and new SMS messages, perform overlay attacks, and prevent users from uninstalling it. The threat also asks for Accessibility Services privileges, which allow it to grant itself further permissions.

The CSIRT said the malware also steals victims’ banking credentials by overlaying fake login pages on top of legitimate ones. Considering that it can also intercept messages and notifications, it allows its operators to bypass SMS-based two-factor authentication and log into the victims’ accounts without alerting them.

“Xenomorph has been found to target 56 internet banking apps, 28 from Spain, 12 from Italy, 9 from Belgium, and 7 from Portugal, as well as Cryptocurrency wallets and general-purpose applications like emailing services. The Fast Cleaner app has now been removed from the Play Store but not before it garnered 50,000+ downloads,” the CSIRT security advisory asserted.

The Nigerian Communications Commission hereby wishes to advise telecom consumers to be on alert in order not to fall victim to this manipulation.

Accordingly, the NCC urges telecom consumers and other Internet users, particularly those using Android-powered devices to use trusted Antivirus solutions and update them regularly to their latest definitions.

The Commission also implore consumers and other stakeholders to always update banking applications to their most recent versions.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Headlines

Dangote Refinery maintains ex-depot price of PMS

Published

on

 

Nasiru Yusuf Ibrahim

Dangote Petroleum Refinery and Petrochemicals Limited has announced that its ex-depot price of Premium Motor Spirit (PMS) remains unchanged, reaffirming its commitment to stability in Nigeria’s domestic energy market.

 

In a statement issued by Esan Sunday, Head of Media Relations, Branding and Communication, the company said sustaining the current price reflects its efforts to cushion the broader economy against external shocks. It noted that by absorbing prevailing cost pressures, the refinery is helping to moderate inflationary risks, promote energy affordability, and ensure uninterrupted fuel supply amid ongoing global uncertainties.

 

The company reiterated its dedication to the steady supply of high-quality petroleum products to the Nigerian market, while aligning with national objectives of price stability and energy security.

 

It also urged the public to rely solely on official communications from the refinery for accurate and up-to-date information regarding its operations and pricing.

 

 

Continue Reading

Headlines

Tinubu congratulates Garo on appointment as Kano deputy governor

Published

on

 

Nasiru Yusuf Ibrahim

 

President Bola Ahmed Tinubu has congratulated Alhaji Murtala Sule Garo on his emergence as the Deputy Governor of Kano State following his swearing-in on Tuesday.

 

KANO FOCUS reports that Garo was sworn in by Governor Abba Kabir Yusuf after being nominated to fill the vacancy created by the resignation of former deputy governor, Comrade Aminu Abdulsalam.

 

In a statement issued by his Special Adviser on Information and Strategy, Bayo Onanuga, the President described Garo’s appointment as a positive step toward strengthening unity within the All Progressives Congress (APC) in Kano State.

 

The President noted that the 48-year-old politician has held several public offices, including Chairman of Kabo Local Government Area and Commissioner for Local Government and Chieftaincy Affairs during the administration of former governor Abdullahi Umar Ganduje. He also served as the APC governorship running mate in the 2023 general elections.

 

Tinubu commended Governor Yusuf for the appointment, urging political stakeholders in the state to rally behind the administration to ensure stability and progress.

 

He also called on the new deputy governor to work closely with the governor in delivering effective leadership and accelerating development in Kano State.

 

The President wished Garo success in his new role.

 

Continue Reading

Headlines

Ganduje acknowledges Sanusi II as Emir of Kano, 6 years after dethroning him

Published

on

 

Ibrahim Khalil

 

A dramatic political moment unfolded in Kano on Tuesday as former governor Abdullahi Umar Ganduje publicly acknowledged Muhammad Sanusi II as the Emir of Kano and Chairman of the Kano State Council of Emirs.

 

KANO FOCUS reports that the unexpected gesture occurred during the swearing-in ceremony of the newly appointed Deputy Governor, Murtala Sule Garo, at Government House, Kano—an event attended by top political leaders and traditional rulers.

 

While delivering his goodwill message, Ganduje addressed Sanusi by his full royal title, drawing immediate attention from dignitaries at the ceremony. The audience responded with loud applause when he greeted the Emir and recognised his position as head of the Kano Emirate Council.

 

The development is particularly significant given the long-standing rift between the two figures. Sanusi was removed from the throne during Ganduje’s administration, a decision that sparked widespread political and legal controversy at the time.

 

However, the political landscape shifted following the emergence of Governor Abba Kabir Yusuf, under whose administration Sanusi was reinstated as Emir of Kano.

 

Observers say Ganduje’s public acknowledgment signals a possible easing of tensions and may point to broader efforts at reconciliation within Kano’s political and traditional institutions.

 

The moment has since been described by analysts as a “twist of fate” in Kano politics, where former rivalries appear to be giving way to cautious gestures of respect among key actors.

 

Continue Reading

Trending