E-Business
ESET Researchers Spot DoubleLocker ‘Innovative’ Android Ransomware

By peter oluka
ESET researchers have spotted the first-ever ransomware misusing Android accessibility services. On top of encrypting data, it also locks the device.
Detected by ESET products as Android/DoubleLocker.A, the ransomware is based on the foundations of a particular banking Trojan, known for misusing accessibility services of the Android operating system.
However, DoubleLocker doesn’t have the functions related to harvesting users’ banking credentials and wiping out their accounts. Instead, it has received two powerful tools for extorting money from its victims.
DoubleLocker can change the device’s PIN, preventing victims from accessing their devices, and also encrypts the data it finds in them – a combination that has not been seen previously in the Android ecosystem.
“Given its banking malware roots, DoubleLocker may well be turned into what could be called ransom-bankers. Two-stage malware that first tries to wipe your bank or PayPal account and subsequently locks your device and data to request a ransom… Speculation aside, we spotted a test version of such a ransom-banker in the wild as long ago as May, 2017,” comments Lukáš Štefanko, the ESET malware researcher who discovered DoubleLocker.
Distribution
DoubleLocker spreads in the very same way as its banking parent does. It is distributed mostly as a fake Adobe Flash Player through compromised websites.
Once launched, the app requests activation of the malware’s accessibility service, named “Google Play Service”. After the malware obtains the accessibility permissions, it uses them to activate device administrator rights and set itself as the default Home application, in both cases without the user’s consent.
“Setting itself as a default home app – a launcher – is a trick that improves the malware’s persistence. Whenever the user clicks on the home button, the ransomware gets activated and the device gets locked again. Thanks to using the accessibility service, the user doesn’t know that they launch malware by hitting Home,” explains Štefanko.
Locking Both Device And Data
DoubleLocker, once executed on the device, creates two reasons for the victims to pay.
First, it changes the device’s PIN, effectively blocking the victim from using it. The new PIN is set to a random value which the attackes neither store nor send anywhere, so it’s impossible for the user or a security expert to recover it. After the ransom is paid, the attacker can remotely reset the PIN and unlock the device.
Second, DoubleLocker encrypts all files from the device’s primary storage directory. It utilizes the AES encryption algorithm, appending the extension “.cryeye”. “The encryption is implemented properly, which means that, unfortunately, there is no way to recover the files without receiving the encryption key from the attackers,” says Štefanko.
The ransom has been set to 0.0130 BTC (approximately USD 54 at time of writing) and the message highlights that it must be paid within 24 hours. However, if the ransom is not paid, the data will remain encrypted and will not be deleted.
How To Get Rid Of It?
In the ransom note, the user is warned against removing or otherwise blocking DoubleLocker: “Without [the software], you will never be able to get your original files back”.
To prevent unwanted removal of the “software”, the crooks even recommend disabling the user’s antivirus software.
“Such advice is irrelevant: all those with a quality security solution installed on their devices are safe from DoubleLocker,” explains Štefanko.
The only viable option to clean the device of the DoubleLocker ransomware is via a factory reset.
For rooted devices, however, there is a method to get past the PIN lock without a factory reset. For the method to work, the device needed to be in the debugging mode before the ransomware got activated.
If this condition is met, then the user can connect to the device by ADB and remove the system file where the PIN is stored by Android. This operation unlocks the screen so that the user can access their device. Then, working in safe mode, the user can deactivate device administrator rights for the malware and uninstall it. In some cases, a device reboot is needed.
As for the data stored on the device, there is no way to recover it, as mentioned earlier.
“DoubleLocker serves as just another reason for mobile users to have a quality security solution installed, and to back up their data on a regular basis,” concludes Štefanko.
E-Business
NDPC Probes UNILAG, Lotus Bank, Hackerbella over Alleged Students’ Data Misuse

Nigeria Data Protection Commission (NDPC) has commenced a forensic investigation into the University of Lagos (UNILAG), Lotus Bank and Hackerbella Ltd over alleged violations of data protection laws involving students’ personal information.

The investigation follows public complaints alleging that students’ personal data were used to open bank accounts without a lawful basis.
Dr Vincent Olatunji, national commissioner and chief executive officer of the NDPC, directed the investigation team to conduct a comprehensive assessment of the circumstances surrounding the collection, processing, use and disclosure of the affected students’ personal data.
The investigation will also determine the respective roles and responsibilities of UNILAG, Lotus Bank and Hackerbella in the alleged processing of the data.
According to the Commission, the investigation will assess the data protection compliance obligations of the parties under the Nigeria Data Protection Act, 2023 (NDP Act), as well as potential risks posed to the rights and freedoms of the affected data subjects.
The NDPC said the probe would cover several areas, including Data Protection Impact Assessments (DPIAs), the lawfulness and transparency of credit scoring or profiling activities, and the use of automated decision-making systems.
It will also examine the adequacy of privacy notices, data-sharing arrangements, lawful bases for processing, data minimisation and purpose limitation.
Other areas include data retention policies and the adequacy of technical and organisational measures put in place to safeguard the rights and personal data of affected students.
The Commission reiterated that institutions entrusted with the personal data of students, staff and other members of their communities have a heightened responsibility to ensure that such information is processed lawfully, fairly, transparently and securely.
The NDPC therefore warned educational institutions that are yet to comply with its existing data protection compliance directives to take immediate steps to achieve compliance.
The Commission said it would continue to exercise its regulatory mandate to protect the privacy rights of Nigerians and ensure that organisations processing personal data comply with the provisions of the Nigeria Data Protection Act, 2023.
E-Business
Microsoft to Unveil Next-generation AI Chip in September

Microsoft is planning to unveil its new Maia 300 AI chip this fall, potentially as soon as next month, The Information reported on Monday, citing people with direct knowledge of the plans.

The company introduced its Maia AI chip in November 2023 but has lagged rivals such as Alphabet and Amazon in scaling up its in-house chip efforts as it seeks to reduce its reliance on Nvidia’s costly processors.
Google began recognizing revenue from direct sales of its custom AI chips, called Tensor Processing Units, in the quarter ended June, while Amazon has also seen growing adoption of its processors, including its Trainium chips.
Microsoft has been in talks with chipmaker TSMC to secure manufacturing capacity for more than 300,000 units of the chip for delivery in 2027, according to the report. It is also looking to significantly ramp up production and persuade major cloud customers such as Anthropic to adopt the chip.
Microsoft ultimately aims to secure capacity for more than 1 million Maia 300 chips, though component supplies and ongoing capacity negotiations with TSMC could constrain its plans, according to the report.
It unveiled its second-generation Maia 200 in January, built by TSMC using 3-nanometer technology.
Microsoft packed the chip with a significant amount of SRAM, a type of memory that can provide speed advantages for AI systems handling large numbers of user requests.
E-Business
X Replaces Revenue Sharing wit New Creator Rewards Programme

X has announced plans to discontinue its Revenue Sharing programme and introduce a new Original Content Rewards programme to reward creators for producing original content on the platform.

The social media company announced the changes at the weekend in a post on its X Creators handle, saying the new programme would reward creators who contribute original content.
“Today, we’re introducing the Original Content Rewards Program, a new way to reward creators who bring original ideas, expertise, reporting, creativity, and commentary to X,” the company said.
X said it would stop accepting new enrolments into the Revenue Sharing programme from Friday, while existing participants would continue earning until September 7, 2026.
“Starting today, we’re no longer accepting new enrollments into Revenue Sharing,” it said.
According to the company, existing Revenue Sharing participants will receive three final payouts, with two scheduled for August 14 and August 28, while the final payment for earnings accrued through September 7 is expected around September 11.
X said existing Revenue Sharing participants would begin getting access to apply for the new programme from September 8, subject to meeting its eligibility requirements.
The first payout under the Original Content Rewards programme will be made on August 28, 2026, while existing Revenue Sharing creators who enrol in the new programme from September 8 will receive their first payment on September 25.
Under the new programme, eligible creators will earn from qualified impressions generated by their original content, with payments made every two weeks.
X defined qualified impressions as unique impressions from Premium users on the Home Timeline feed, where at least 50 per cent of a post is visible.
On the other hand, “The following are excluded from qualified impressions: impressions from the same account counted more than once per post; paid, promoted, or artificially generated impressions; and fraudulent impressions,” it said.
To qualify, creators must be at least 18 years old, live in a country where the programme is available, maintain an account in good standing and have either a personal or vusiness account.
They must also subscribe to X Premium, Premium+ or Premium Business, have at least 500 verified followers and record at least 500,000 Home Timeline impressions from verified users within the previous 90 days.
X said creators must also regularly post original content to remain eligible.
“We want to recognize creators who break news, share expertise, tell stories, create entertainment, and contribute meaningful perspectives to the conversation,” the company said.
The platform said original content could include threads, videos, memes, graphics, illustrations, reporting, analysis, commentary and reactions that add meaningful value to existing conversations.
It said creators who use content produced by others would need to add meaningful commentary, context, analysis, humour or creative transformation for such posts to qualify.
“Building on existing conversations is a core part of X, but simply reposting someone else’s content is not enough,” it said.
X said minor edits such as cropping, filters, borders, watermarks, speed adjustments or simple text overlays would generally not qualify as meaningful transformation on their own.
It also warned that content copied or substantially reproduced from another creator, content downloaded and re-uploaded from X or another platform without being the original author’s, automated content, disinformation and misleading content would be ineligible.
The company said accounts that violate the programme’s requirements could be temporarily or permanently removed from it, depending on the severity of the violation.
It added that creators would be responsible for ensuring they had the necessary rights, permissions or licences to use content created by others.
“Original content is content you personally create that reflects your own voice, perspective, expertise, or creativity,” X said.
The company said the new programme was intended to reward creators who make the platform more valuable by bringing original ideas and perspectives to its conversations.
“The Original Content Rewards Program is designed to reward the creators who start them, shape them, and move them forward,” it said.
E-Business3 days agoX Replaces Revenue Sharing wit New Creator Rewards Programme
Telecom3 days agoMTN Alerts Subscribers over Fake 25GB Anniversary MTN Data Giveaway
E-Financial3 days agoInterswitch, Temenos Commit to Advancing Nigeria’s Digital Banking Technology
E-Financial3 days agoFG Spent N3.1 Trillion on Domestic Debt Servicing in Q1- DMO
General News3 days agoFake Agency: ICPC Indicts NITDA, Others over Inadequate Due Diligence
General News3 days agoUNESCO Taps Oguamanam,Nigerian Scholar to Advisory Body on Science, Tech Ethics
General News3 days agoTax Reform Built on Taxing Prosperity, Not Poverty– Adedeji
News2 days agoMoove Achieves Unicorn Status With $250m Funding




















