Malware
BreakingHighlightTop StoryTrending Story

NCC warns android phone users against new damaging malware, “Flubot”

646

 

By Ajuma Edwina Ameh

“The malware is circulated through Short Message Service (SMS) and can snoop “on incoming notifications, initiate calls, read or write SMSes, and transmit the victim’s contact list to its control centre”

“Flubot also impersonates Android mobile banking applications to steal personal data, credit card details or online banking credentials’

“It attacks Android devices by pretending to be “FedEx, DHL, Correos, and Chrome applications” and compels unsuspecting users to alter the accessibility configurations on their devices in order to maintain continuous presence on devices”

The Nigerian Communications Commission (NCC) has alerted android phone users in the country of the existence of new, high-risk and extremely-damaging Malware called “Flubot”.

The Director of Public Affairs of NCC, Dr Ikechukwu Adinde, who gave the warning in a statement issued on Friday, said information received from the Nigeria Computer Emergency Response Team (ngCERT), revealed that Flubot “targets Androids with fake security updates and App installations.

Adinde said the malware is circulated through Short Message Service (SMS) and can snoop “on incoming notifications, initiate calls, read or write SMSes, and transmit the victim’s contact list to its control centre.”

According to him, Flubot also impersonates Android mobile banking applications to steal personal data, credit card details or online banking credentials.

“It attacks Android devices by pretending to be “FedEx, DHL, Correos, and Chrome applications” and compels unsuspecting users to alter the accessibility configurations on their devices in order to maintain continuous presence on devices.

“The new malware undermines the security of devices by copying fake login screens of prominent banks, and the moment the users enter their login details on the fake pages, their data is harvested and transmitted to the malware operators’ control point from where the data is exploited by intercepting banking-related One Time Passwords (OTPs) and replacing the default SMS app on the targeted Android device.

“Consequently, it secures admittance into the device through SMS and proceeds to transmit similar messages to other contacts that may be on the device it has attacked enticing them into downloading the fake app.

“It suffices to say that, when Flubot infects a device, it can result in incalculable financial losses.

“Additionally, the malware creates a backdoor which grants access to the user’s device, thus enabling the invader or attacker to perform other criminal actions, including launching other variants of malware,” the statement explained.

The NCC further listed different ways telecom consumers can protect themselves from the attack.

“In view of this discovery and understanding of the process by which this malware operates, and in order to protect millions of telecom consumers and prevent criminal forces, irrespective of location, from using telecom platforms to perpetrate fraud and irredeemable damages, the NCC hereby wishes to reiterate the advisory of ngCERT as follows;

“Do not click on the link if you receive a suspicious text message, and do not install any app or security update the page asks you to install; Use updated antivirus software that detects and prevents malware infections; Apply critical patches to the system and application.

“Use strong passwords and enable Two-Factor Authentication (2FA) over logins; Back-up your data regularly; If you have been affected by this campaign, you should reset your device to factory mode as soon as possible. This will delete any data on your phone, including personal data.

“Do not restore from backups created after installing the app. You may contact ngCERT on *incident@cert.gov.ng* for technical assistance. You will also need to change the passwords to all of your online accounts, with urgency, around your online bank accounts.

“If you have concerns that your accounts may have been accessed by unauthorised people, contact your bank immediately,” it said.

 

 

Leave a comment

Related Articles

17 Days to Go: Access Bank Lagos City Marathon Unveils Key Details

With the 2026 Access Bank Lagos City Marathon just 17 days away,...

FG to Recall Military Retirees to Secure High-Risk “Ungoverned Spaces”

The Federal Government has launched a strategic initiative to deploy military veterans...

Boardroom Titan, Business Mogul Otunba Adekunle Ojora Exits

Renowned Lagos patriarch Otunba Adekunle Ojora has died at 93. The Olori...

FCTA Strike: NLC Defies Court Order, Tells Workers to Continue Action

The Nigeria Labour Congress (NLC) has signaled its intent to continue industrial...

Bilateral Milestone: Nigeria and Türkiye Commit to $5bln Trade Volume, Counter-Terrorism Cooperation

In a strategic move to fortify economic and security ties, Türkiye and...

“A mere stumble, not a fall” — Bayo Onanuga clarifies Pres. Tinubu’s Ankara incident

Following a minor stumble during his reception in Ankara, the Presidency has...

Alleged Coup: Military Can’t Try Treason Under Armed Forces Act – Frank Tietie

Abuja-based human rights lawyer Frank Tietie has cautioned that the Nigerian military...

Court Ruling: Return to Work or Face Consequences – FCT Minister Wike

Following a court-ordered end to the FCTA workers strike, Minister Nyesom Wike...

ECOWAS: Halting A Drift Towards Disintegration and Looming Civil War in Guinea-Bissau

by Paul Ejime More than 50 years after its formation, the Economic...

Total Blackout: National Grid Fails for Second Time in 96 Hours

For the second time in just four days, Nigeria’s national grid suffered...

Unions, CSOs to NAFDAC: Lift the Sachet Alcohol Ban or Face a Shutdown

Stakeholders in the food and beverage industry are escalating their opposition to...

At Last, DHQ Confirms Thwarted Coup Plot, 16 Officers Set for Martial Court

The Defence Headquarters (DHQ) announced on Monday that a Special Investigative Panel...

Sunday Igboho Ends 4-Year Self-Exile, Returns to Ibadan

After about four years in self-imposed exile, Yoruba Nation activist Chief Sunday...

“Wike Must Go’ Chants Echo as FCTA Workers Protest at Abuja Court

Federal Capital Territory Administration (FCTA) workers, backed by the Nigeria Labour Congress...

Kado Dawn Raid: One Suspect Shot, Arrested After FCT Police Bust Motorists’ Robbery

The early morning calm and quietness of the Kado district in the...

Tinubu Departs Abuja Jan. 26 for High-Level State Visit to Türkiye

President Bola Tinubu will depart Abuja on Monday, January 26, for a...

Bayelsa Operation: DSS Arrests 2 Sea Pirates, Foils Crude Oil Vessel Hijack

A DSS intelligence-led operation in Bayelsa State has uncovered a criminal network...

Tinubu’s Minister Warns APC Against Ditching VP Shettima on 2027 Presidential Ticket

Hannatu Musawa, the Minister of Culture, Tourism, and Creative Economy, has warned...

Panic Grips Residents as Fire Sweeps Through Lagos Estate

A major fire broke out on Saturday at the Amuwo Odofin Industrial...

VP Shettima Back in Abuja After High-Level Engagements Abroad

After a week-long diplomatic and economic mission to Guinea-Conakry and Switzerland, Vice...