News
BlueNoroff Targets Eecutives on Windows and MacOS Using AI-driven Tools

At the Security Analyst Summit in Thailand, Kaspersky’s Global Research and Analysis Team (GReAT) unveiled the latest BlueNoroff APT activity through two highly targeted malicious campaigns ‘GhostCall’ and ‘GhostHire’. The ongoing operations have been targeting Web3 and cryptocurrency organisations across India, Turkiye, Australia and other countries in Europe and Asia since at least April 2025.

BlueNoroff, a subdivision of the notorious Lazarus group, continues to expand its signature ‘SnatchCrypto’ campaign, a financially motivated operation which targets crypto industries worldwide. The newly described GhostCall and GhostHire campaigns employ new infiltration techniques and customised malware to compromise blockchain developers and executives. These attacks affect macOS and Windows systems as primary targets and are managed through a unified command-and-control infrastructure.
The GhostCall campaign focuses on macOS devices, beginning with a highly sophisticated and personalised social engineering attack. The attackers reach out via Telegram, impersonating venture capitalists and in some cases using compromised accounts of real entrepreneurs and startup founders to promote investment or partnership opportunities. The victims are invited to fake investment meetings on phishing sites mimicking Zoom or Microsoft Teams during which they are prompted to “update” their client to fix an audio issue, this action downloads a malicious script and deploys a malware infection on the device.
“This campaign relied on deliberate and carefully planned deception. Attackers replayed videos of previous victims during staged meetings to make the interaction appear like a real call and manipulate new targets. The data collected in this process is then used not only against the initial victim but also exploited to enable subsequent and supply-chain attacks, leveraging established trust relationships to compromise a broader range of organisations and users,” comments Sojun Ryu, security researcher at Kaspersky GReAT.
Attackers deployed seven multi-stage execution chains, four which were previously unseen, to distribute a range of new customised payloads, including crypto stealers, browser credential stealers, secrets stealer, and Telegram credential stealers.
In the GhostHire campaign the APT targets blockchain developers by posing as recruiters. Victims are tricked into downloading and running a GitHub repository containing malware, presented as a skill assessment. GhostHire shares its infrastructure and tools with the GhostCall campaign, but instead of using video calls, it focuses on approaching hands-on developers and engineers through fake recruitment. After initial contact, victims are added to a Telegram bot that delivers either a ZIP file or a GitHub link, along with a short deadline to complete the task. Once executed, the malware installs itself on the victim’s machine, customised for the operating system.
The use of generative AI has enabled BlueNoroff to accelerate malware development and refine its attack techniques. The attackers introduced new programming languages and added additional features, complicating detection and analysis tasks. It further enables the actor to manage and expand its operations, increasing both the complexity and scale of attacks.
“Since its previous campaigns, the threat actor’s targeting strategy has evolved beyond simple cryptocurrency and browser credential theft. The use of generative AI has significantly accelerated this process, enabling easier malware development with reduced operational overhead.
“This AI-driven approach helps to fill the gaps in available information, enabling more focused targeting. By combining compromised data with AI’s analytical capabilities, the scope of these attacks has expanded. We hope our research will contribute to preventing further harm,” comments Omar Amin, senior security researcher at Kaspersky GReAT.
News
Union Bank Secures Global Payment Data Security Certification

Union Bank of Nigeria has secured certification under the Payment Card Industry Data Security Standard (PCI DSS) version 4.0.1, a global standard for protecting payment card data.

The certification took effect on August 11, 2026, confirming that the bank’s systems for storing, processing and transmitting customers’ credit and debit card information meet stringent international security requirements.
PCI DSS certification is designed to reduce the risk of payment card data breaches and financial fraud while strengthening customer confidence in electronic payment systems.
The assessment covered key areas of Union Bank’s operations, including network infrastructure, card issuance, ATM and POS transactions, payment processing, reconciliation, settlement, chargebacks, dispute resolution and retail banking.
Union Bank was assessed and certified under the Service Provider category.
The certification process lasted a full year and involved quarterly assessments, with support from departmental, business and functional heads across the bank. Digital security firm Digital Encode supported the process, while the final independent audit was conducted by CyberCube, an accredited Qualified Security Assessor.
Yetunde B. Oni, Managing Director and Chief Executive Officer of Union Bank, said the certification demonstrates the bank’s commitment to protecting customer information.
“The security of our customers’ information is central to everything we do at Union Bank. This certification reaffirms that our payment systems and processes meet a rigorous global standard, and it reflects the discipline of colleagues across the Bank who work every day to keep customer data safe.”
The renewal also ensures that Union Bank maintains continuous PCI DSS certification, in line with the Central Bank of Nigeria’s requirement for banks to sustain compliance without interruption.
News
Access Holdings Sets New Benchmark in Nigeria’s Finance Talent Pipeline

New data from CFA Society Nigeria is reshaping how the country’s financial sector thinks about talent development, with Access emerging as the single largest source of CFA candidates in Nigeria, distinction industry watchers say signals a deeper shift in how leading institutions are building investment expertise from within.

In its Where Nigeria’s Finance Professionals Work series, published in a national daily, CFA Society Nigeria placed Access first among employers of CFA candidates nationwide, with 82 candidates enrolled in the programme, more than double the 38 recorded at the next-placed institution and well ahead of every other bank or financial services firm on the list.
Access also ranked second among employers of CFA charterholders, with 11 professionals who have completed all three levels of the Programme and met its experience and ethics requirements.
For an industry that has long measured itself by balance sheet size and branch count, the rankings point to a different kind of competition: one over who is building the deepest bench of certified, globally credentialed talent.
CFA Society Nigeria compiled the data from its Salesforce Membership Database as at June 2026, and described the exercise as a way of recognising employers whose people “bring rigour, integrity and global best practices into the workplace every day.”
Analysts following the sector say the outcome is notable less for the ranking itself than for what it suggests about talent strategy across Africa’s financial services industry. A single institution developing more aspiring charterholders than the rest of the market combined raises the floor for professional standards nationally, not just within one balance sheet.
Every candidate who advances through the CFA Programme adds to a shared pool of ethics-trained, analytically rigorous professionals that Nigeria’s capital markets, pension funds and asset managers all eventually draw from.
Access Holdings Group Chief Executive Officer Innocent C. Ike, commenting on the rankings, framed the achievement in terms of institution-building rather than recruitment: “Every candidate on that list represents our commitment to building institutions and professionals that endure.”
The remark echoes a broader thesis increasingly voiced by market observers, that talent depth, not scale alone, is what will determine which African financial institutions earn lasting global credibility.
That distinction sits at the centre of Access’s stated ambition to become the World’s Most Respected African Financial Services Group. If the CFA numbers are any indication, the Group’s route to that goal runs less through square metres of branch network and more through the calibre of the people sitting inside it, a bet that Nigeria’s finance professionals, and the institutions that will one day hire them, are already placing alongside Access.
News
NCAA to Introduce RFID Technology to Tackle Missing Luggages

Nigeria Civil Aviation Authority (NCAA) has announced plans to introduce Radio Frequency Identification (RFID) baggage tracking technology across domestic and international airport terminals to tackle the growing problem of delayed, misrouted and missing luggages

Michael Achimugu, director, Public Affairs and Consumer Protection, NCAA, disclosed this at a stakeholder engagement forum in Lagos.
Achimugu said the RFID-enabled system would replace the traditional barcode-based baggage tracking framework and provide airlines and passengers with real-time visibility of checked luggage from check-in to final collection.
According to him, the technology would improve baggage traceability, reduce mishandling and strengthen accountability across the baggage-handling chain.
Unlike conventional barcode systems, RFID technology allows baggage to be automatically scanned at multiple points without requiring direct line of sight, enabling real-time tracking of luggage throughout its journey.
Achimugu said issues involving short-landed, missing, lost or damaged baggage had remained among the major complaints from air travellers, alongside flight delays.
He said the introduction of RFID technology was therefore aimed at improving baggage-handling standards and restoring passenger confidence in the aviation sector.
The NCAA said the initiative also aligns with IATA Resolution 753, which requires airlines to track baggage at key points during the passenger journey.
The authority expects the technology to provide more accurate information on the location of luggage, facilitate quicker resolution of baggage-related complaints and improve the overall passenger experience.
The NCAA said the initiative would also strengthen accountability among airlines and other stakeholders involved in baggage handling at Nigerian airports.
News3 days agoNCAA to Introduce RFID Technology to Tackle Missing Luggages
General News3 days agoNigeria Not Making Progress in Fiscal Transparency –US
Telecom3 days agoGSMA Industry Services Unveils Circularity Services to Help Operators Reduce E-Waste and Unlock Value
Telecom3 days agoMTN Nigeria Unveils Y’ello Street Museum to Mark 25 Years of Connectivity
News3 days agoFirm Urges MSMEs to Increase Digital Payments Adoption for Growth
E-Financial3 days agoSEC Directs Operators to Subscribe to NigSac Alerts, Freeze Terrorists-Linked Funds
Telecom1 day agoAirtel Nigeria Adds Over 1,000Cell Sites in Nationwide Expansion to Surpasses 17,000
E-Financial3 days agoAFC Raises $430m in Digital Bond to Deepens Digital Financial Infrastructure
















