Connect with us

News

HP Wolf Security Threat Insights Report Shows How Cybercriminals Are Tricking Users

Published

on

Kindly share this post

HP Inc. has released its latest global HP Wolf Security Threat Insights Report, providing analysis of real-world cybersecurity attacks. By isolating threats that have evaded detection tools and made it to user endpoints, HP Wolf Security has specific insight into the latest techniques being used by cybercriminals.

The HP Wolf Security threat research team identified a wave of attacks utilizing Excel add-in files to spread malware, helping attackers to gain access to targets, and exposing businesses and individuals to data theft and destructive ransomware attacks.

There was a huge six-fold increase (+588%) in attackers using malicious Microsoft Excel add-in (.xll) files to infect systems compared to last quarter – a technique found to be particularly dangerous as it only requires one click to run the malware.

The team also found adverts for .xll dropper and malware builder kits on underground markets, which make it easier for inexperienced attackers to launch campaigns.

Additionally, a recent QakBot spam campaign used Excel files to trick targets, using compromised email accounts to hijack email threads and reply with an attached malicious Excel (.xlsb) file.

Advertisement

After being delivered to systems, QakBot injects itself into legitimate Windows processes to evade detection.

Malicious Excel (.xls) files were also used to spread the Ursnif banking Trojan to Italian-speaking businesses and public sector organizations through a malicious spam campaign, with attackers posing as Italian courier service BRT. New campaigns spreading Emotet malware are now using Excel instead of JavaScript or Word files too.

Other notable threats isolated by the HP Wolf Security threat insight team include:

  • The return of TA505? HP identified a MirrorBlast email phishing campaign sharing many tactics, techniques, and procedures (TTPs) with TA505, a financially motivated threat group known for massive malware spam campaigns and monetizing access to infected systems using ransomware. The attack targeted organizations with the FlawedGrace Remote Access Trojan (RAT).
  • Fake gaming platform infecting victims with RedLine: A spoofed Discord installer website has been discovered, tricking visitors into downloading the RedLine infostealer and stealing their credentials.
  • Switching up uncommon file types is still bypassing detection: The Aggah threat group targeted Korean-speaking organizations with malicious PowerPoint add-in (.ppa) files disguised as purchase orders, infecting systems with remote access Trojans. PowerPoint malware is unusual, making up 1% of malware.

“Abusing legitimate features in software to hide from detection tools is a common tactic for attackers, as is using uncommon file types that may be allowed past email gateways.

Security teams need to ensure they are not relying on detection alone and that they are keeping up with the latest threats and updating their defenses accordingly.

For example, based on the spike in malicious .xll sightings we are seeing, I’d urge network administrators to configure email gateways to block incoming .xll attachments, only permit add-ins signed by trusted partners or disable Excel add-ins entirely,” explains Alex Holland, Senior Malware Analyst, HP Wolf Security threat research team, HP Inc.

Advertisement

“Attackers are continually innovating to find new techniques to evade detection, so it’s vital that enterprises plan and adjust their defenses based on the threat landscape and the business needs of their users. Threat actors have invested in techniques such as email thread hijacking, making it harder than ever for users to tell friend from foe.”

The findings are based on data from the many millions of endpoints running HP Wolf Security. HP Wolf Security tracks malware by opening risky tasks in isolated, micro Virtual Machines (micro-VMs) to understand and capture the full infection chain, helping to mitigate threats that have slipped past other security tools.

This has let customers click on over 10 billion email attachments, web pages, and downloads with no reported breaches. By better understanding the behaviour of malware in the wild, HP Wolf Security researchers and engineers can bolster endpoint security protection and overall system resilience.

Other key findings in the report include:

  • 13% of email malware isolated had bypassed at least one email gateway scanner.
  • Threats used 136 different file extensions in their attempts to infect organizations.
  • 77% of malware detected was delivered via email, while web downloads were responsible for 13%.
  • The most common attachments used to deliver malware were documents (29%), archives (28%), executables (21%), spreadsheets (20%).
  • The most common phishing lures were related to the New Year or business transactions such as “Order”, “2021/2022”, “Payment”, “Purchase”, “Request” and “Invoice”.

“Today, low-level threat actors can carry out stealthy attacks and sell access onto organized ransomware groups, leading to large-scale breaches that could cripple IT systems and grind operations to a halt,” comments Dr. Ian Pratt, Global Head of Security for Personal Systems, HP Inc.

“Organizations should focus on reducing the attack surface and enabling quick recovery in the event of compromise. This means following Zero Trust principles and applying strong identity management, least privilege and isolation from the hardware level.

Advertisement

For example, by isolating common attack vectors such as email, browsers or downloads using micro-virtualization, any potential malware or exploits lurking within are contained, rendering them harmless.”

Kindly share this post

Dear Reader, Your support matters. But we believe that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. That is why, we have devoted our energy to independent reportage of technology and finance and how they affect lives. Our incisive and analytical view of how technology news affects the daily life help individuals and organizations make up their minds. Quality journalism costs money. Today, we're asking that you support us to do more. Kindly support our effort to deliver technology and finance journalism to everyone in the world. Donate as little as N1,000. Bank transfers can be made to: UBA Plc 1017156876 Communication Week Media Ltd

News

Access Holdings Sets New Benchmark in Nigeria’s Finance Talent Pipeline

Published

on

Kindly share this post

New data from CFA Society Nigeria is reshaping how the country’s financial sector thinks about talent development, with Access emerging as the single largest source of CFA candidates in Nigeria, distinction industry watchers say signals a deeper shift in how leading institutions are building investment expertise from within.

In its Where Nigeria’s Finance Professionals Work series, published in a national daily, CFA Society Nigeria placed Access first among employers of CFA candidates nationwide, with 82 candidates enrolled in the programme, more than double the 38 recorded at the next-placed institution and well ahead of every other bank or financial services firm on the list.

Access also ranked second among employers of CFA charterholders, with 11 professionals who have completed all three levels of the Programme and met its experience and ethics requirements.

For an industry that has long measured itself by balance sheet size and branch count, the rankings point to a different kind of competition: one over who is building the deepest bench of certified, globally credentialed talent.

CFA Society Nigeria compiled the data from its Salesforce Membership Database as at June 2026, and described the exercise as a way of recognising employers whose people “bring rigour, integrity and global best practices into the workplace every day.”

Advertisement

Analysts following the sector say the outcome is notable less for the ranking itself than for what it suggests about talent strategy across Africa’s financial services industry. A single institution developing more aspiring charterholders than the rest of the market combined raises the floor for professional standards nationally, not just within one balance sheet.

Every candidate who advances through the CFA Programme adds to a shared pool of ethics-trained, analytically rigorous professionals that Nigeria’s capital markets, pension funds and asset managers all eventually draw from.

Access Holdings Group Chief Executive Officer Innocent C. Ike, commenting on the rankings, framed the achievement in terms of institution-building rather than recruitment: “Every candidate on that list represents our commitment to building institutions and professionals that endure.”

The remark echoes a broader thesis increasingly voiced by market observers, that talent depth, not scale alone, is what will determine which African financial institutions earn lasting global credibility.

That distinction sits at the centre of Access’s stated ambition to become the World’s Most Respected African Financial Services Group. If the CFA numbers are any indication, the Group’s route to that goal runs less through square metres of branch network and more through the calibre of the people sitting inside it, a bet that Nigeria’s finance professionals, and the institutions that will one day hire them, are already placing alongside Access.

Advertisement

Kindly share this post
Continue Reading

News

NCAA to Introduce RFID Technology to Tackle Missing Luggages

Published

on

Kindly share this post

Nigeria Civil Aviation Authority (NCAA) has announced plans to introduce Radio Frequency Identification (RFID) baggage tracking technology across domestic and international airport terminals to tackle the growing problem of delayed, misrouted and missing luggages

NCAA to Introduce RFID Technology to Tackle Missing Luggages

Michael Achimugu, director, Public Affairs and Consumer Protection, NCAA, disclosed this at a stakeholder engagement forum in Lagos.

Achimugu said the RFID-enabled system would replace the traditional barcode-based baggage tracking framework and provide airlines and passengers with real-time visibility of checked luggage from check-in to final collection.

According to him, the technology would improve baggage traceability, reduce mishandling and strengthen accountability across the baggage-handling chain.

Unlike conventional barcode systems, RFID technology allows baggage to be automatically scanned at multiple points without requiring direct line of sight, enabling real-time tracking of luggage throughout its journey.

Advertisement

Achimugu said issues involving short-landed, missing, lost or damaged baggage had remained among the major complaints from air travellers, alongside flight delays.

He said the introduction of RFID technology was therefore aimed at improving baggage-handling standards and restoring passenger confidence in the aviation sector.

The NCAA said the initiative also aligns with IATA Resolution 753, which requires airlines to track baggage at key points during the passenger journey.

The authority expects the technology to provide more accurate information on the location of luggage, facilitate quicker resolution of baggage-related complaints and improve the overall passenger experience.

The NCAA said the initiative would also strengthen accountability among airlines and other stakeholders involved in baggage handling at Nigerian airports.

Advertisement

 

Kindly share this post
Continue Reading

News

Firm Urges MSMEs to Increase Digital Payments Adoption for Growth

Published

on

Kindly share this post

eTranzact International Plc has called for increased adoption of digital payment solutions among micro, small and medium enterprises (MSMEs), saying access to technology is critical to improving business efficiency, financial inclusion and growth.

The company also said it was deepening its partnership with the Small and Medium Enterprises Development Agency of Nigeria (SMEDAN) to expand digital access and financial literacy among small businesses across the country.

In a statement, the Divisional Head, Merchant Services, eTranzact, Mrs. Abimbola Reis, stated this at the SMEDAN/eTranzact Town Hall Engagement in Lagos recently, themed, “Financial Literacy and Inclusion for MSMEs Leveraging on Fintech Innovation.”

Reis described MSMEs as the backbone of Nigeria’s economy, noting that the sector comprises almost 40 million businesses and contributes significantly to economic growth and job creation.

However, she said many businesses continue to face challenges including limited access to finance, inefficient payment systems, weak financial reporting, cash-flow constraints and inadequate access to digital platforms.

Advertisement

She added that trust concerns also affect businesses’ ability to access finance, while heavy reliance on cash increases exposure to theft and makes payment reconciliation more difficult.

Representing the Director-General of SMEDAN, Prof. Yinka Fisher said the town hall was aimed at generating practical ideas and solutions that would support the growth and expansion of MSMEs.

“The essence of this engagement is to share ideas and concepts that will help MSMEs thrive and expand. Our partnership with eTranzact is about expanding the frontiers of MSMEs and ensuring they continue to grow,” he said.

Also speaking, representative of the Director-General of the Nigerian Association of Chambers of Commerce, Industry, Mines and Agriculture (NACCIMA), Dr. Praise Adedigba said businesses could no longer depend solely on hard work to remain competitive.

Advertisement

Kindly share this post
Continue Reading

Trending