Connect with us

Telecom

Beware of New Ransomware- Sophos Warns

Published

on

Kindly share this post

Sophos, a global leader in endpoint and network security, has released alert about a new ransomware that is threatening businesses.

 

SophosLabs Uncut released detailed malware analysis of the new ransomware called MegaCortex, On Friday, May 3, 2019, at 3:45 pm ET.

 

Sophos research team expatiating on the ransomeware writes:

Advertisement

 

“MegaCortex was a relatively little-seen malware that suddenly spiked in volume on May 1. Sophos has seen MegaCortex detections in the US, Canada, Argentina, Italy, the Netherlands, France, Ireland, Hong Kong, Indonesia, and Australia.

 

“The ransomware has manual components similar to Ryuk and BitPaymer, but the adversaries behind MegaCortex use more automated tools to carry out the attack – this is unique.

 

Advertisement

“Up until now, Sophos has seen automated attacks, manual attacks and blended attacks, which typically lean more towards using manual hacking techniques to move laterally; with MegaCortex, Sophos is seeing heavier use of automation coupled with the manual component.

 

“This new formula is designed to spread the infection to more victims, more quickly.

 

As indicated in the SophosLabs Uncut article, MegaCortex Ransomware Wants to be TheOne, there is no explicit value for the ransom demand in the ransom note.

Advertisement

 

The attackers invite victims to email them on either of two free mail.com email addresses and send along a file that the ransomware drops on the victim’s hard drive to request decryption “services.”

 

The ransom note also promises the cybercriminals “will include a guarantee that your company will never be inconvenienced by us,” if the victims pay the ransom, and continues, “You will also receive a consultation on how to improve your companies cyber security.”

 

Advertisement

Sophos has also made the following protection recommendation to businesses:

 

“It appears that there’s a strong correlation between the presence of MegaCortex, and a pre-existing, ongoing infection on the victims’ networks with both Emotet and Qbot. If IT managers are seeing alerts about Emotet or Qbot infections, those should take a high priority. Both of those bots can be used to distribute other malware, and it’s possible that’s how the MegaCortex infections got their start.

 

“Sophos has not seen any indication so far that Remote Desktop Protocol (RDP) has been abused to break into networks, but we know that holes in enterprise firewalls that allow people to connect to RDP remain relatively common. We strongly discourage this practice and suggest that any IT admin who wishes to do this put the RDP machine behind a VPN

Advertisement

 

“As the attack seems to indicate that an administrative password was abused by the criminals, we also recommend the widespread adoption of two-factor authentication wherever possible

 

“Keeping regular backups of your most important and current data on an offline storage device is the best way to avoid having to pay a ransom

 

Advertisement

“Use anti-ransomware protection, such as Sophos Intercept X, to block MegaCortex and future ransomware

 

Commenting on the study, Sophos Senior Security Advisor John Shier, said:

 

“We suspect this is your script kiddie/living-off-the-land ‘mega bundle’ and a good example of what we’ve lately been calling cybercriminal pen-testing.

Advertisement

 

“The MegaCortex attackers have taken the blended threat approach and turned it up to 11, by increasing the automated component to target more victims. Once they have your admin credentials, there’s no stopping them. Launching the attack from your own domain controller is a great way for the attackers to inherit all the authority they need to impact everything in an organization.

 

“Organizations need to pay attention to basic security controls and perform security assessments, before the criminals do, to prevent attackers like these from slipping through”.

Advertisement

Kindly share this post

Ugo Onwuaso is an ICT enthusiast. He believes technology should be used for general good. He holds a Master of Public Administration (MPA) degree from the Lagos state University. Dear Reader, Your support matters. But we believe that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. That is why, we have devoted our energy to independent reportage of technology and finance and how they affect lives. Our incisive and analytical view of how technology news affects the daily life help individuals and organizations make up their minds. Quality journalism costs money. Today, we're asking that you support us to do more. Kindly support our effort to deliver technology and finance journalism to everyone in the world. Donate as little as N1,000. Bank transfers can be made to: UBA Plc 1017156876 Communication Week Media Ltd

Telecom

NCC Asks Telcos to Make Budgetary Provisions for Cybersecurity

Published

on

Kindly share this post

Nigerian Communications Commission (NCC) has directed telecommunications operators to make dedicated budgetary provisions for cybersecurity as part of efforts to strengthen the resilience of Nigeria’s communications infrastructure against the growing wave of cyber threats.

NCC Asks Telcos to Make Budgetary Provisions for Cybersecurity

 

The directive forms part of the Commission’s Cyber Resilience Framework for the Nigerian Communications Sector (CRF-NCS), which introduces new governance, risk management and operational requirements aimed at safeguarding the country’s critical telecommunications infrastructure from increasingly sophisticated cyberattacks.

Under the framework, all licensed telecom operators are expected to establish formal cybersecurity governance structures, dedicate adequate financial resources to cyber resilience programmes, and integrate cybersecurity into their enterprise-wide risk management processes.

The Commission said operators must ensure cybersecurity investments are no longer treated as optional operational expenses but as strategic business priorities necessary to protect network infrastructure, customer information and the country’s digital economy.

Advertisement

According to the NCC, licensees are expected to allocate sufficient budgets to support cyber risk assessments, security technologies, staff training, incident response capabilities, continuous monitoring and compliance with regulatory requirements.

The framework also requires operators to designate senior executives responsible for cybersecurity oversight.

At the same time, boards of directors are expected to provide strategic direction and ensure adequate funding for cyber resilience initiatives.

Speaking on the need for a stronger cybersecurity regime during the unveiling of the framework, Abraham Oshadami, executive commissioner, Technical Services, NCC,  said, “Given the increasing digitalisation of services, the rapid growth of data exchange, and the sophisticated nature of modern cyber threats, the need for a robust, adaptive and inclusive cybersecurity framework has become more urgent.”

He added, “Both state and non-state actors are targeting essential sectors—including ours—through coordinated cyber and physical attacks. These attacks frequently target control systems and data integrity, underscoring the critical risks posed to operational technology (OT), especially in our sector.”

Advertisement

“As cyber threats evolve, they endanger not only system performance but also human safety, amplifying the severity and consequences of disruptions to vital communications infrastructure. Cybersecurity now encompasses human safety and must address the real risk to people’s lives when a system is attacked or compromised.”

The Commission further stated that operators are required to develop comprehensive cybersecurity implementation plans, conduct periodic risk assessments, establish business continuity and disaster recovery procedures, and regularly test their cyber defence capabilities.

In addition, the framework makes cyber incident reporting compulsory. Licensees must inform the NCC’s CSIRT of any major cybersecurity breach within four hours of discovery, and provide a thorough post-incident analysis after mitigation is complete.

 

Advertisement

Kindly share this post
Continue Reading

Telecom

Glo Leads Internet Growth Figures in Nigeria for May

Published

on

Kindly share this post

Digital solution provider, Globacom has recorded the highest Internet subscriber growth among Nigeria’s major telecom companies for the month of May.

Data from the Nigerian Communications Commission, NCC, Nigeria’s total Internet users increased to 157 million in May, up from 154.3 million in April. That is a growth of 2.67 million users in one month.

Globacom led the market by adding about 1.2 million new Internet subscribers. This means Glo was responsible for almost half of all new Internet users in May.

The company’s subscriber base grew from 15.5 million in April to 16.8 million in May. Airtel came second with 1.07 million new users, moving from 54.8 million to 55.8 million. MTN added 382,894 users to reach 83.5 million.

T2 Mobile, formerly 9mobile, recorded no growth for the second month in a row. Its subscriber base remained at 802,534. This is despite its roaming agreement with MTN, which was approved almost a year ago to help T2 customers use MTN’s network in areas with poor coverage.

Advertisement

Industry experts say Glo’s strong growth is due to its ongoing network upgrade. Since last year, the company has been building new base stations, expanding its fibre network, and adding thousands of new 4G sites across cities and rural areas.

The upgrades have improved voice and data quality for customers, while Globacom remain committed to providing better network experience and affordable Internet services to more Nigerians.

Kindly share this post
Continue Reading

Telecom

MTN Paid 600Bn in Taxes in H1 2026 – Kadri, MTN CFO

Published

on

Kindly share this post

MTN Nigeria’s half-year 2026 performance reflects more than revenue growth, highlighting the wider economic activity generated through tax payments, infrastructure investment and shareholder returns.

MTN Paid 600 Billion in Taxes in H1 2026 - Kadri, MTN CFO

Kadri, MTN CFO

Beyond its financial results, the telecommunications operator said it continues to channel substantial resources into expanding network infrastructure, meeting statutory obligations and delivering value across its stakeholder ecosystem.

The company disclosed that it paid more than ₦600 billion in taxes, customs duties, regulatory levies and other statutory obligations over the past year.

It also invested over ₦1.6 trillion in capital expenditure since January 2025 to expand network capacity and improve service quality, while declaring an interim dividend of ₦26 per share for shareholders.

Speaking on Arise News’ Global Business Report, MTN Nigeria’s Chief Financial Officer, Modupe Kadri, explained that the company’s earnings are shared across several stakeholders before returns reach investors. “For every one naira of revenue, about 24 kobo becomes profit.

“The government receives over ₦600 billion through taxes and levies, operating costs account for a significant portion of our revenue, and every participant within the ecosystem benefits from the value we create,” he said.

Advertisement

According to the Nigerian Communications Commission (NCC), telecommunications remains one of the largest contributors to Nigeria’s Gross Domestic Product, supporting digital financial services, education, healthcare, commerce and public services. Continued investment by operators has also been identified as critical to expanding broadband access and improving digital inclusion across the country.

Kadri noted that shareholder returns remain an important part of MTN’s capital allocation strategy, but stressed that they represent only one aspect of the company’s broader economic contribution.

“Even when we declare dividends, the government still receives withholding tax, while we continue investing heavily in our network because sustaining quality service requires ongoing capital commitment,” he said.

Kindly share this post
Continue Reading

Trending