E-Business
Check Point Identifies New Banking, MaliBot Malwares that Poses Danger for Users of Mobile Banking

Check Point Research (CPR), the Threat Intelligence arm of Check Point Software Technologies, a leading provider of cyber security solutions globally, has published its latest Global Threat Index for June 2022. CPR reports that a new Android banking malware has emerged, named MaliBot, following the takedown of FluBot at the end of May.

Although only just discovered, MaliBot, a banking, has already reached third place in the most prevalent mobile malwares list. It disguises itself as cryptocurrency mining applications under different names and targets users of mobile banking to steal financial information.
Similar to FluBot, MaliBot uses phishing SMS messages (smishing) to lure victims into clicking on a malicious link that redirects them to the download of a fake application containing the malware.
Also this month, the notorious malware, Emotet, is still the most prevalent malware overall. Snake Keylogger comes in third after an increase in activity since appearing in eighth place last month. Snake’s main functionality is to record users keystrokes and transmit collected data to threat actors.
While in May CPR witnessed Snake Keylogger being delivered via PDF files, recently it has been spread through emails containing Word attachments tagged as requests for quotations. Researchers also reported about new variant of Emotet in June that has credit card stealing capabilities and targets Chrome browser users.
“While it’s always good to see law enforcement successful in bringing down cybercrime groups or malwares like FluBot, sadly it didn’t take long for a new mobile malware to take its place,” said Maya Horowitz, VP Research at Check Point Software.
“Cybercriminals are well aware of the central role that mobile devices play in many peoples’ lives and are always adapting and improving their tactics to match. The threat landscape is evolving rapidly, and mobile malware is a significant danger for both personal and enterprise security. It’s never been more important to have a robust mobile threat prevention solution in place.”
CPR also revealed that “Apache Log4j Remote Code Execution” is the most commonly exploited vulnerability, impacting 43% of organizations worldwide, closely followed by “Web Server Exposed Git Repository Information Disclosure” which has a global impact of 42.3%. “Web Servers Malicious URL Directory Traversal” is in third place with a global impact of 42.1%.
Top Malware Families
This month, Emotet is still the most popular malware with a global impact of 14%, followed by Formbook and Snake Keylogger, each impacting 4.4% of organizations worldwide.
In Nigeria, Ramnit has a country impact of 14.10% followed by Phorpiex at 10.26% and Formbook at 8.97%.
- Emotet – Emotet is an advanced, self-propagating and modular Trojan. Emotet was once used as a banking Trojan, but recently is used as a distributer to other malware or malicious campaigns. It uses multiple methods for maintaining persistence and evasion techniques to avoid detection. In addition, it can be spread through phishing spam emails containing malicious attachments or links.
- Phorpiex – Phorpiex is a botnet (aka Trik) that has been active since 2010 and at its peak controlled more than a million infected hosts. It is known for distributing other malware families via spam campaigns as well as fueling large-scale spam and sextortion campaigns.
- Formbook – FormBook is an Infostealer targeting the Windows OS and was first detected in 2016. It is marketed as Malware as a Service (MaaS) in underground hacking forums for its strong evasion techniques and relatively low price. FormBook harvests credentials from various web browsers, collects screenshots, monitors and logs keystrokes, and can download and execute files according to orders from its C&C.
Top Attacked Industries Globally
This month Education/Research is still the most attacked industry globally, followed by Government/Military and Healthcare. In Africa ISP/MSP is the most industry this month, followed by Communications and Government/Military.
- ISP/MSP
- Communications
- Government/Military
Top Exploited Vulnerabilities
This month, “Apache Log4j Remote Code Execution” is the most commonly exploited vulnerability, impacting 43% of organizations worldwide, closely followed by “Web Server Exposed Git Repository Information Disclosure” which has a global impact of 42.3%. “Web Servers Malicious URL Directory Traversal” is in third place with a global impact of 42.1%.
↑ Apache Log4j Remote Code Execution (CVE-2021-44228) – A remote code execution vulnerability exists in Apache Log4j. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the affected system.
- ↑ Web Server Exposed Git Repository Information Disclosure – An information disclosure vulnerability has been reported in Git Repository. Successful exploitation of this vulnerability could allow an unintentional disclosure of account information.
- ↓ Web Servers Malicious URL Directory Traversal (CVE-2010-4598,CVE-2011-2474,CVE-2014-0130,CVE-2014-0780,CVE-2015-0666,CVE-2015-4068,CVE-2015-7254,CVE-2016-4523,CVE-2016-8530,CVE-2017-11512,CVE-2018-3948,CVE-2018-3949,CVE-2019-18952,CVE-2020-5410,CVE-2020-8260) – There exists a directory traversal vulnerability on different web servers. The vulnerability is due to an input validation error in a web server that does not properly sanitize the URL for the directory traversal patterns. Successful exploitation allows unauthenticated remote attackers to disclose or access arbitrary files on the vulnerable server.
Top Mobile Malwares
This month AlienBot is the most prevalent mobile malware, followed by Anubis and MaliBot.
- AlienBot – AlienBot malware family is a Malware-as-a-Service (MaaS) for Android devices that allows a remote attacker, as a first step, to inject malicious code into legitimate financial applications. The attacker obtains access to victims’ accounts, and eventually completely controls their device.
- Anubis – Anubis is a banking Trojan designed for Android mobile phones. Since it was initially detected, it has gained additional functions including Remote Access Trojan (RAT) functionality, keylogger, audio recording capabilities and various ransomware features. It has been detected on hundreds of different applications available in the Google Store.
- MaliBot – Malibot is an Android Banking malware that has been spotted targeting users in Spain and Italy. The Banking disguises itself as crypto mining applications under different names and focuses on stealing financial information, crypto wallets and more personal data.
Check Point’s Global Threat Impact Index and its ThreatCloud Map is powered by Check Point’s ThreatCloud intelligence. ThreatCloud provides real-time threat intelligence derived from hundreds of millions of sensors worldwide, over networks, endpoints and mobiles. The intelligence is enriched with AI-based engines and exclusive research data from Check Point Research, The Intelligence & Research Arm of Check Point Software Technologies.
E-Business
Cyber Resilience a Critical Priority for Manufacturing Amid Rapid Digitalization – Report Shows

As 60% of manufacturers race toward full digitalisation, cyber risk is increasingly manifesting as a business risk, according to a new global report by Kaspersky and VDC Strategy.

This means cybersecurity is not merely a compliance function, it is a cornerstone of production assurance, safeguarding uptime, quality, and operational continuity.
Manufacturers are modernising to deliver safer, more consistent and more cost-effective production and digitalization is moving fast: just 9% of organisations describe themselves as fully digital today, but 60% expect to get there within two years, according to the joint report by Kaspersky and VDC, titled ‘Cyber Resilience, Built for Manufacturing’.
That shift links shop-floor equipment, production lines and site operations to platforms such as Manufacturing execution systems (MES), Supervisory control and data acquisition (SCADA) and historians, turning many plants into cyber-physical systems (CPS), where a digital disruption doesn’t stay digital. It can slow production lines, quarantine work in progress, invalidate traceability records, or halt production outright.
What’s driving manufacturing digitalization?
Manufacturers are digitising for measurable operational gains, not novelty. Survey respondents identified the primary drivers of their digital transformation strategy as:
- Improving production output or efficiency (24%)
- Reducing operational or production expenses (15%)
- Enabling new strategic opportunities (14%)
- Improving cyber resilience (13%)
The same connected systems that unlock these gains, including MES, IIoT sensors, automated material handling, remote engineering access, also become the systems that determine whether production can be trusted to keep running.
Cyber risk is now a business risk
Cyber risk has evolved from a mere IT concern to a direct threat to revenue generation, as environments transform into cyber-physical systems. In these integrated settings, digital disruptions like malware no longer just affect data, they can cause unsafe operations, scrapped batches, and halted production on the plant floor. This shift highlights the urgent need to treat cybersecurity as a key part of operational resilience.
According to the report, nearly 60% of manufacturing organisations estimate that cyber incidents cause damages exceeding $1 million per event, with an average disruption of 15.3 hours. The most significant losses often result from production halts, missed delivery commitments, and penalties, rather than just forensic costs.
In this context, downtime links cybersecurity risks to overall business performance. Cyber incidents can reduce Overall Equipment Effectiveness (OEE), strain staffing, and disrupt supply chains. Recovery involves more than system restore, it requires re-establishing confidence in process parameters, quality records, and traceability before resuming operations.
Mature cybersecurity programs now incorporate OT security into governance, focusing on metrics valued by production leaders such as time to restore, backup confidence, legacy asset coverage, and safe degraded operation. This alignment ensures cybersecurity supports continuous production and resilience, not just IT compliance.
However, challenges remain due to split ownership. While 59% of organisations’ IT departments manage security policies, these often overlook plant realities. Managing many security tools (44%) and OT patching issues (38%) show that cybersecurity must be embedded into daily routines of production, engineering, and quality teams. Only through such integration can cybersecurity effectively enhance operational reliability and defend against evolving threats.
“As manufacturing environments become increasingly interconnected, cybersecurity shifts focus from merely adding protective layers to ensuring the availability, resilience, and integrity of production processes. The goal is to minimise operational impact and speed up recovery, rather than solely preventing intrusions.
“Kaspersky offers a unified ecosystem that integrates IT, OT, and IIoT security, empowering manufacturers to pursue digital transformation securely. This strategy helps maintain operational continuity and reduces long-term cybersecurity costs,” comments Andrey Strelkov, Head of Industrial Cybersecurity Product Line at Kaspersky.
To implement this strategy, manufacturing companies can leverage solutions from the Kaspersky OT Cybersecurity Ecosystem, centered around Kaspersky Industrial CyberSecurity (KICS), a native Extended Detection and Response platform designed for critical infrastructure protection. KICS enables centralised detection and response to complex attacks across the entire industrial network, ensuring comprehensive visibility and security.
E-Business
NDPC Probes UNILAG, Lotus Bank, Hackerbella over Alleged Students’ Data Misuse

Nigeria Data Protection Commission (NDPC) has commenced a forensic investigation into the University of Lagos (UNILAG), Lotus Bank and Hackerbella Ltd over alleged violations of data protection laws involving students’ personal information.

The investigation follows public complaints alleging that students’ personal data were used to open bank accounts without a lawful basis.
Dr Vincent Olatunji, national commissioner and chief executive officer of the NDPC, directed the investigation team to conduct a comprehensive assessment of the circumstances surrounding the collection, processing, use and disclosure of the affected students’ personal data.
The investigation will also determine the respective roles and responsibilities of UNILAG, Lotus Bank and Hackerbella in the alleged processing of the data.
According to the Commission, the investigation will assess the data protection compliance obligations of the parties under the Nigeria Data Protection Act, 2023 (NDP Act), as well as potential risks posed to the rights and freedoms of the affected data subjects.
The NDPC said the probe would cover several areas, including Data Protection Impact Assessments (DPIAs), the lawfulness and transparency of credit scoring or profiling activities, and the use of automated decision-making systems.
It will also examine the adequacy of privacy notices, data-sharing arrangements, lawful bases for processing, data minimisation and purpose limitation.
Other areas include data retention policies and the adequacy of technical and organisational measures put in place to safeguard the rights and personal data of affected students.
The Commission reiterated that institutions entrusted with the personal data of students, staff and other members of their communities have a heightened responsibility to ensure that such information is processed lawfully, fairly, transparently and securely.
The NDPC therefore warned educational institutions that are yet to comply with its existing data protection compliance directives to take immediate steps to achieve compliance.
The Commission said it would continue to exercise its regulatory mandate to protect the privacy rights of Nigerians and ensure that organisations processing personal data comply with the provisions of the Nigeria Data Protection Act, 2023.
E-Business
Microsoft to Unveil Next-generation AI Chip in September

Microsoft is planning to unveil its new Maia 300 AI chip this fall, potentially as soon as next month, The Information reported on Monday, citing people with direct knowledge of the plans.

The company introduced its Maia AI chip in November 2023 but has lagged rivals such as Alphabet and Amazon in scaling up its in-house chip efforts as it seeks to reduce its reliance on Nvidia’s costly processors.
Google began recognizing revenue from direct sales of its custom AI chips, called Tensor Processing Units, in the quarter ended June, while Amazon has also seen growing adoption of its processors, including its Trainium chips.
Microsoft has been in talks with chipmaker TSMC to secure manufacturing capacity for more than 300,000 units of the chip for delivery in 2027, according to the report. It is also looking to significantly ramp up production and persuade major cloud customers such as Anthropic to adopt the chip.
Microsoft ultimately aims to secure capacity for more than 1 million Maia 300 chips, though component supplies and ongoing capacity negotiations with TSMC could constrain its plans, according to the report.
It unveiled its second-generation Maia 200 in January, built by TSMC using 3-nanometer technology.
Microsoft packed the chip with a significant amount of SRAM, a type of memory that can provide speed advantages for AI systems handling large numbers of user requests.
Telecom2 days agoipNX Joins Calls for Innovation-Friendly Ecosystem and Stronger Local Opportunities at Regenesys AI Summit
E-Business2 days agoNDPC Probes UNILAG, Lotus Bank, Hackerbella over Alleged Students’ Data Misuse
News2 days agoPalmPay Reinforces Commitment to Youth Empowerment on International Youth Day
Telecom2 days agoNCC Reports over 5,000 Fibre Cuts in 6 Months
E-Financial2 days agoKudiWave Asks for Clarification over N750m Transfer from PalmPay Account
Telecom2 days agoGoogle Selects Six Nigerian News Creators for Emerging Voices Growth Lab
E-Financial2 days agoNigerians Borrow More to Buy Homes as Mortgage Demand Climbs – CBN
General News2 days agoNUPRC Warns of Counterfeit, AI-Generated Appointment Letters




















