Connect with us

News

Check Point Research Reveals XLoader as August’s Top Malware in Nigeria

Published

on

Kindly share this post

Check Point Research (CPR), the Threat Intelligence arm of Check Point® Software Technologies, a provider of cyber security solutions globally, has published its latest Global Threat Index for August 2022.

 

In Nigeria, XLoader is the most widespread malware this month impacting 14.47% of organisations in the country, followed by Phorpiex and Guloader both with 6.58%.

Globally, CPR reports that FormBook is now the most prevalent malware, taking over from Emotet, which has held that position since its reappearance in January.

FormBook is an Infostealer targeting Windows OS which, once deployed, can harvest credentials, collect screenshots, monitor and log keystrokes as well as download and execute files according to its command and control (C&C) orders.

Advertisement

Since it was first spotted in 2016, it has continued to make a name for itself, marketed as a Malware as a Service (MaaS) in underground hacking forums, known for its strong evasion techniques and relatively low price.

August also saw a rapid increase in GuLoader activity, which resulted in it being the fourth most widespread malware. GuLoader was initially used to download Parallax RAT but has since been applied to other remote access trojans and infostealers such as Netwire, FormBook and Agent Tesla.

It is commonly distributed through extensive email phishing campaigns, that lure the victim into downloading and opening a malicious file, allowing the malware to get to work.

Additionally, Check Point Research reports that Joker, an Android spyware, is back in business and has claimed third place in the top mobile malware list this month. Once Joker is installed, it can steal SMS messages, contact lists and device information as well as sign the victim up for paid premium services without their consent. Its rise can partially be explained by an uplift in campaigns as it was recently spotted to be active in some Google Play Store applications.

“The shifts that we see in this month’s index, from Emotet dropping from first to fifth place to Joker becoming the third most prevalent mobile malware, is reflective of how fast the threat landscape can change” said Maya Horowitz, VP Research at Check Point Software.

Advertisement

“This should be a reminder to individuals and companies alike, of the importance of keeping up to date with the most recent threats as knowing how to protect yourself is essential.

“Threat actors are constantly evolving and the emergence of FormBook shows that we can never be complacent about security and must adopt a holistic, prevent-first approach across networks, endpoints and the cloud.”

CPR also revealed this month that the Education/Research sector is still the most targeted industry by cybercriminals globally. With Government/Military and Healthcare taking second and third place as the most attacked sectors.

“Apache Log4j Remote Code Execution” returns to first place as the most exploited vulnerability, impacting 44% of organizations worldwide, after overtaking “Web Server Exposed Git Repository Information Disclosure” which had an impact of 42%.

Top malware families

Advertisement

*The arrows relate to the change in rank compared to the previous month.

FormBook is the most widespread malware this month impacting 5% of organizations worldwide, followed by AgentTesla with an impact of 4% and XMRig with 2%.

  1. XLoader – XLoader is an Android Spyware and Banking Trojan developed by the Yanbian Gang, a Chinese hacker group. This malware uses DNS spoofing to distribute infected Android apps to collect personal and financial information..
  2. Phorpiex – Phorpiex is a botnet (aka Trik) that has been active since 2010 and at its peak controlled more than a million infected hosts. It is known for distributing other malware families via spam campaigns as well as fueling large-scale spam and sextortion campaigns.
  3. Guloader – GuLoader is a downloader that has been widely used since December 2019. When it first appeared, GuLoader was used to download Parallax RAT but has been applied to other remote access trojans and info-stealers such as Netwire, FormBook, and Agent Tesla.

Top Attacked Industries Globally

This month the Education/Research sector remained in first place as the most attacked industry globally, followed by Government/Military and Healthcare.

  1. Education/Research
  2. Government/Military
  3. Healthcare

Top Exploited Vulnerabilities

This month, “Apache Log4j Remote Code Execution” is the most common exploited vulnerability, impacting 44% of organizations globally, followed by “Web Server Exposed Git Repository Information Disclosure” which dropped from first place to second with an impact of 42%. “Web Servers Malicious URL Directory Traversal” remains in the third place, with a global impact of 39%.

  1. Apache Log4j Remote Code Execution (CVE-2021-44228) – A remote code execution vulnerability exists in Apache Log4j. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the affected system.
  2. Web Server Exposed Git Repository Information Disclosure – An information disclosure vulnerability has been reported in Git Repository. Successful exploitation of this vulnerability could allow unintentional disclosure of account information.
  3. ↔ Web Servers Malicious URL Directory Traversal (CVE-2010-4598,CVE-2011-2474,CVE-2014-0130,CVE-2014-0780,CVE-2015-0666,CVE-2015-4068,CVE-2015-7254,CVE-2016-4523,CVE-2016-8530,CVE-2017-11512,CVE-2018-3948,CVE-2018-3949,CVE-2019-18952,CVE-2020-5410,CVE-2020-8260) – There exists a directory traversal vulnerability on different web servers. The vulnerability is due to an input validation error in a web server that does not properly sanitize the URI for the directory traversal patterns. Successful exploitation allows unauthenticated remote attackers to disclose or access arbitrary files on the vulnerable server.

Top Mobile Malwares

This month AlienBot is the most prevalent Mobile malware, followed by Anubis and Joker.

Advertisement
  1. AlienBot – AlienBot is a banking Trojan for Android, sold underground as a Malware-as-a-Service (MaaS). It supports keylogging, dynamic overlays for credentials theft, as well as SMS harvesting for 2FA bypass. Additional remote control capabilities are provided by using a TeamViewer module.
  2. Anubis – Anubis is a banking Trojan malware designed for Android mobile phones. Since it was initially detected, it has gained additional functions including Remote Access Trojan (RAT) functionality, keylogger and audio recording capabilities as well as various ransomware features. It has been detected on hundreds of different applications available in the Google Store.
  3. Joker – An Android Spyware in Google Play, designed to steal SMS messages, contact lists and device information. Furthermore, the malware can also sign the victim up for paid premium services without their consent or knowledge.

Check Point’s Global Threat Impact Index and its ThreatCloud Map is powered by Check Point’s ThreatCloud intelligence. ThreatCloud provides real-time threat intelligence derived from hundreds of millions of sensors worldwide, over networks, endpoints and mobiles. The intelligence is enriched with AI-based engines and exclusive research data from Check Point Research, The Intelligence & Research Arm of Check Point Software Technologies.

Kindly share this post

Dear Reader, Your support matters. But we believe that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. That is why, we have devoted our energy to independent reportage of technology and finance and how they affect lives. Our incisive and analytical view of how technology news affects the daily life help individuals and organizations make up their minds. Quality journalism costs money. Today, we're asking that you support us to do more. Kindly support our effort to deliver technology and finance journalism to everyone in the world. Donate as little as N1,000. Bank transfers can be made to: UBA Plc 1017156876 Communication Week Media Ltd

News

DataPro Upgrades Dangote Cement’s Credit Rating to AA+

Published

on

Kindly share this post

DataPro Rating Agency has upgraded the long-term credit rating of Dangote Cement Plc to AA+ from AA, citing the company’s strong financial performance, market leadership and ability to meet its financial obligations despite Nigeria’s challenging economic environment.

In its latest rating report, the technology-driven credit rating agency also affirmed Dangote Cement’s short-term rating at A1, with a Stable Outlook. The ratings are valid until June 16, 2027.

DataPro said the upgrade reflects the cement maker’s sustained financial strength, resilient operating performance and dominant position in Nigeria and across Africa.

According to the agency, the assessment followed a comprehensive review of the company’s capital base, earnings, liquidity, corporate governance, regulatory compliance and the sustainability of its financial performance over the medium to long term.

It noted that Dangote Cement’s strong brand, leading market share, solid earnings, robust asset base and experienced management continue to strengthen its ability to meet financial commitments on time.

Advertisement

The agency also highlighted the company’s outstanding financial performance in 2025.

According to the report, Dangote Cement posted N4.31 trillion in revenue during the year, representing a 20 per cent increase from the previous year. Profit before tax more than doubled, rising 109 per cent to N1.53 trillion, driven by higher sales, improved operating efficiency, lower finance costs and a stronger capital structure.

DataPro said the AA+ long-term rating indicates low credit risk and reflects excellent financial strength, business profile and operating performance relative to its rating benchmarks.

It added that the A1 short-term rating signifies good credit quality and shows that the company has a strong capacity to meet its short-term financial obligations as they fall due.

The rating agency, however, noted that the credit rating has a maximum shelf life of 12 calendar months in line with international best practice and should be used only as a reference, not as an offer to trade in securities or as a substitute for investors’ independent judgement.

Advertisement

 

Kindly share this post
Continue Reading

News

Xora Finance, Fintech Firm Refuses to Hire Nigerians over Alleged Dishonesty

Published

on

Kindly share this post

Xora Finance has announced it will no longer consider job applicants from Nigeria.

 

Xora Finance is a digital bank founded by Joren Lundgren, in February 2026 and allows users to deposit and earn interest on their XRP cryptocurrency.

Lundgren, founder, in an announcement on X (formerly Twitter), cited an ongoing pattern of misconduct, such as dishonesty and theft, from previous Nigerian hires as the reason for the decision.

This sudden blanket ban came just days after the company’s official career page was aggressively recruiting remote workers for marketing and content roles.

Advertisement

The announcement generated heavy backlash online, with many people upset that a blanket rule punishes honest job seekers.

 

 

 

Advertisement

Kindly share this post
Continue Reading

News

How Ponzi Scheme Victims can Seek Legal Remedies — Lawyers

Published

on

Kindly share this post

Some lawyers have said that victims of Ponzi schemes have legal remedies, although recovering lost funds and prosecuting perpetrators remain major challenges.

How Ponzi Scheme Victims can Seek Legal Remedies — Lawyers

A Ponzi scheme is an investment fraud that pays existing investors with funds collected from new participants rather than from actual profits.

Operators lure victims by promising high returns with little to no risk.

The scheme inevitably collapses when the flow of new investors slows down.

Some lawyers who spoke to News Agency of Nigeria (NAN) separate interviews with on Sunday, said that victims could pursue civil actions to recover their money.

Advertisement

Mr Chibuikem Opara, a lawyer at Justification Chambers, Ikeja,said many Nigerians continued to fall victim to Ponzi schemes in spite of repeated warnings.

Opara said it was wrong to attribute participation in Ponzi schemes to a lack of investment opportunities, noting that promoters often exploit investors’ greed through promises of unrealistic returns.

“What you cannot take away is the fact that many Nigerians have fallen and continue to fall victim to these schemes every time,” he said.

According to him, victims may individually or collectively institute civil actions against the beneficiary company for breach of contract or refund arising from failure of consideration.

Opara said victims could also unite to seek an order from the Federal High Court to wind up the beneficiary company.

Advertisement

He, however, noted that such efforts might yield little benefit if perpetrators had already siphoned the funds and left behind an empty shell.

The lawyer said available remedies largely depended on the actions of relevant authorities, adding that recipient accounts could be frozen to facilitate fund recovery and support winding-up proceedings.

Opara said regulators and law enforcement agencies often became aware of Ponzi schemes only after substantial losses had occurred.

According to him, victims frequently failed to report suspicious schemes early enough to enable timely intervention.

He added that funds are sometimes moved outside the country before authorities become aware of the fraud.

Advertisement

Opara also cited inadequate information and the deceptive nature of the schemes as major obstacles to investigation and prosecution.

“Most times, everything about the schemes is made to appear elusive, just like the profits promised to victims,” he said.

Also speaking, Mr Vincent Aminu of A.F. Aminu and Co. advised that victims of investment scams should report such cases to appropriate law enforcement agencies on time.

Aminu said victims could petition the Economic and Financial Crimes Commission (EFCC) or file reports with the police.

He said that after investigation, prosecutors could bring charges against suspects under relevant fraud-related laws, including provisions of the Criminal Code and the Advance Fee Fraud and Other Fraud Related Offences Act.

Advertisement

Beyond criminal prosecution, Aminu said .victims could pursue civil actions to recover their money

According to him, such actions may be based on breach of contract, unjust enrichment, or fraudulent misrepresentation, depending on the circumstances.

He added that victims could petition the Securities and Exchange Commission (SEC), which could investigate illegal operators, shut down unauthorised platforms, and freeze assets.

He identified the anonymity of online fraudsters as one of the biggest challenges confronting investigators.

According to him, many operators concealed their identities through fake digital profiles and technologies that made tracking them difficult.

Advertisement

Aminu also noted that victims who delayed taking legal action risked losing opportunities for redress.

He added that prolonged court proceedings often delayed justice for victims.

“Many fraud-related cases take years before the court reaches a verdict, thereby delaying justice for victims,” he said.

Also, Mr Chris Ayiyi of Ayiyi Chambers, Apapa, described Ponzi schemes as a gamble that benefited early participants at the expense of later investors.

Ayiyi said some early entrants received returns on their investments, thereby encouraging others to join the schemes.

Advertisement

He said the schemes eventually collapsed, leaving late investors to bear the losses

The lawyer called for a complete ban on Ponzi schemes or sustained public enlightenment campaigns against them.

He urged the National Assembly to enact laws that would strengthen regulation and provide greater protection for investors.

According to him, stronger legal safeguards are necessary in a country operating a capital-based economy.

Advertisement

Kindly share this post
Continue Reading

Trending