Connect with us

E-Business

XLoader Prevalent Malware in Nigeria, Impacting 14% of Organizations – CPR

Published

on

Kindly share this post

Check Point Research (CPR), the Threat Intelligence arm of Check Point® Software Technologies Ltd., a provider of cybersecurity solutions globally, has published its latest Global Threat Index for September 2022.

CPR reports that In Nigeria, XLoader is the most prevalent malware impacting 14.06% of organizations in the country, followed by Ramnit 10.94% and Phorpiex 9.38%. While Formbook is still the most prevalent malware, impacting 3% of organizations worldwide, Vidar is now in eighth position, up seven places from August.

Vidar is an infostealer designed to give threat actors backdoor access, enabling them to steal sensitive banking information, login credentials, IP addresses, browser history and crypto wallets from infected devices.

The increase in its prevalence follows a malicious campaign whereby fake Zoom websites, such as zoomus website and zoom-download, were used to lure innocent users into downloading the malware. Formbook, an infostealer targeting Windows OS, remains in first place.

Since the onset of the Russia-Ukraine war, CPR has continued to monitor the impact on cyberattacks in both countries.

Advertisement

While the conflict intensifies, CPR’s Global Threat Index for September noted a significant change in the ‘threat rank’ of many Eastern European countries. The threat rank represents how much an organization is being attacked in a specific country compared to the rest of the world.

During September, Ukraine had jumped 26 places, Poland and Russia moved up 18 places each, and both Lithuania and Romania moved up 17 places, among others. All these countries are now among the top 25, with the biggest degradation in their ranking occurring in the past month.

“As the war on the ground continues, so too does the war in cyberspace. It’s likely no coincidence that the threat ranks of many Eastern European countries have increased this last month. All organizations are at risk and must shift to a prevent-first cybersecurity strategy before it’s too late,” commented Maya Horowitz, VP Research at Check Point.

“In terms of the most prevalent malwares in September, it’s interesting to see Vidar leap into the top ten after a long absence. Users of Zoom need to stay alert to fraudulent links as this is how the Vidar malware has been distributed lately. Always keep an eye out for inconsistencies or misspelled words in URLs. If it looks suspicious, it probably is.”

CPR also revealed that “Web Server Exposed Git Repository Information Disclosure” is the most commonly exploited vulnerability, impacting 43% of organizations worldwide, closely followed by “Apache Log4j Remote Code Execution” which dropped from first place to second, with an impact of 42%. September also saw Education/Research remain in first place as the most attacked industry globally.

Advertisement

Top Malware Families

*The arrows relate to the change in rank compared to the previous month.

This month, Formbook is still the most prevalent malware impacting 3% of organizations worldwide, followed by XMRig and AgentTesla which both impact 2% of organizations globally.

In Nigeria, XLoader is the most prevalent malware impacting 14.06% of organizations in the country, followed by Ramnit 10.94% and Phorpiex 9.38%.

  1. XLoader – XLoader is an Android Spyware and Banking Trojan developed by the Yanbian Gang, a Chinese hacker group. This malware uses DNS spoofing to distribute infected Android apps to collect personal and financial information.
  2. Ramnit – Ramnit is a modular banking Trojan first discovered in 2010. Ramnit steals web session information, giving its operators the ability to steal account credentials for all services used by the victim, including bank accounts, and corporate and social networks accounts. The Trojan uses both hardcoded domains as well as domains generated by a DGA (Domain Generation Algorithm) to contact the C&C server and download additional modules.
  3. Phorpiex – Phorpiex is a botnet (aka Trik) that has been active since 2010 and at its peak controlled more than a million infected hosts. It is known for distributing other malware families via spam campaigns as well as fueling large-scale spam and sextortion campaigns.

Top Attacked Industries

In Africa, this month the ISP/MSP sector remains in first place as the most attacked industry globally, followed by Government/Military and Communications

Advertisement
  1. ISP/MSP
  2. Government/Military
  3. Communications

Top Exploited Vulnerabilities

This month, “Web Server Exposed Git Repository Information Disclosure” is the most commonly exploited vulnerability, impacting 43% of organizations globally. It is followed by “Apache Log4j Remote Code Execution” which dropped from first place to second and impacts 42% of organizations. “Command Injection Over HTTP Linux System Files Information Disclosure” jumps into third place, with a global impact of 40%.

  1. ↑ Web Server Exposed Git Repository Information Disclosure – An information disclosure vulnerability has been reported in Git Repository. Successful exploitation of this vulnerability could allow unintentional disclosure of account information.
  2. Apache Log4j Remote Code Execution (CVE-2021-44228) – A remote code execution vulnerability exists in Apache Log4j. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the affected system.
  3. ↑ Command Injection Over HTTP (CVE-2021-43936,CVE-2022-24086)  A command Injection over HTTP vulnerability has been reported. A remote attacker can exploit this issue by sending a specially crafted request to the victim. Successful exploitation would allow an attacker to execute arbitrary code on the target machine.

Top Mobile Malwares

This month, Anubis jumped into first place as the most widespread Mobile malware, followed by Hydra and Joker.

  1. Anubis – Anubis is a banking Trojan malware designed for Android mobile phones. Since it was initially detected, it has gained additional functions including Remote Access Trojan (RAT) functionality, keylogger and audio recording capabilities as well as various ransomware features. It has been detected on hundreds of different applications available in the Google Store.
  2. Hydra – Hydra is a banking Trojan designed to steal finance credentials by requesting victims to enable dangerous permissions.
  3. Joker – An Android Spyware in Google Play, designed to steal SMS messages, contact lists and device information. Furthermore, the malware can also sign the victim up for paid premium services without their consent or knowledge.

Check Point’s Global Threat Impact Index and its ThreatCloud Map is powered by Check Point’s ThreatCloud intelligence. ThreatCloud provides real-time threat intelligence derived from hundreds of millions of sensors worldwide, over networks, endpoints and mobiles. The intelligence is enriched with AI-based engines and exclusive research data from Check Point Research, The Intelligence & Research Arm of Check Point Software Technologies.

Kindly share this post

Dear Reader, Your support matters. But we believe that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. That is why, we have devoted our energy to independent reportage of technology and finance and how they affect lives. Our incisive and analytical view of how technology news affects the daily life help individuals and organizations make up their minds. Quality journalism costs money. Today, we're asking that you support us to do more. Kindly support our effort to deliver technology and finance journalism to everyone in the world. Donate as little as N1,000. Bank transfers can be made to: UBA Plc 1017156876 Communication Week Media Ltd

E-Business

Tinubu Orders NIMC to Enrol Every Nigerian by End of this Year – DG

Published

on

Kindly share this post

President Bola Tinubu has directed the National Identity Management Commission (NIMC) to ensure that every Nigerian is enrolled in the national identity database before the end of 2026, according to Abisoye Coker-Odusote, director general and chief executive officer of the agency.

Tinubu Orders NIMC to Enrol Every Nigerian by End of this Year - DG

Abisoye Coker-Odusote, director general and chief executive officer, NIMC

Coker-Odusote, who appeared on Channels Television, said the directive forms part of the federal government’s efforts to establish a comprehensive national identity system capable of supporting effective governance, planning, and service delivery.

“The President has given us till the end of this year to make sure that we capture every single Nigerian,” she said.

According to her, NIMC is working with partners under the World Bank-supported Identification for Development (ID4D) project to accelerate nationwide enrolment.

“What we have done is we have partnered through the World Bank ID4D project with front-end partners. They are part of the digital identity ecosystem. These are private citizens that we’ve enabled and given jobs to enrol citizens on our behalf,” she explained.

She stressed that the National Identification Number (NIN) remains a unique identifier, ensuring that every individual is registered only once.

Advertisement

“That’s why it’s called a unique identifier, so that you’re only enrolled once,” the NIMC DG added.

Coker-Odusote said Nigeria’s actual population remains uncertain, with estimates ranging from 200 million to 250 million, making a comprehensive identity database essential for national planning.

“It is estimated that we’re 200 million. When we’re done enrolling, we will then know the actual numbers that we have. Some estimates say 230 million, while a few people say 250 million.

“Your identity is basically the foundation for effective governance and service delivery. How can you plan if you don’t know the total number of persons that you have? We have been mandated by Mr President to go down to the community levels to enrol every single Nigerian”, she said.

Responding to concerns about whether an individual could obtain multiple identities by registering in different locations or under different names, the NIMC boss said the commission’s biometric verification system prevents such occurrences.

Advertisement

She explained that while the previous system could accept duplicate enrolments before detecting them later, the current process automatically identifies and invalidates multiple registrations.

“The legacy system had no way of verifying at the front end whether you had already been captured. Once the record comes into the system, it flags it as a duplicate or that the person already exists in the database.

“You would only have one identity generated for you. The other record goes into a deduplication bucket where it is invalidated,”  she said.

The NIMC DG added that biometric verification, including fingerprints and facial recognition, makes it virtually impossible for one person to maintain multiple identities.

“Absolutely. One of the things that this Act has done is to cement our role in capturing biometrics. Private and public sector organisations will no longer capture biometrics independently. They will validate identities through API integration with NIMC.

Advertisement

“The telcos are already doing that with us. If you need a SIM card, they capture your facial biometrics, which are matched against our database in real time to confirm that you are who you claim to be. We’re using biometric validation to tighten security around identity confirmation,” she said.

The remarks come weeks after Tinubu signed the National Identity Management Commission (NIMC) Act 2026 into law on June 26, repealing the 2007 legislation.

The new law reinforces the “One Person, One Identity” policy by making the NIN the country’s foundational identity credential for accessing government and essential private services, including banking, passport applications, tax administration, pensions, land transactions, and consumer credit.

It also introduces stiffer penalties for identity theft, multiple registrations and unauthorised access to personal identity data, while strengthening data privacy protections and granting NIMC wider powers to investigate identity-related offences.

 

Advertisement

Kindly share this post
Continue Reading

E-Business

Kaspersky Warns of AI Risks for World Cup Fans

Published

on

Kindly share this post

Cybersecurity and privacy experts are raising concerns around the growing trend of sports fans using generative AI to create World Cup-related images, mock-ups, predictions and social media content.

Whilst offering new ways for supporters to engage with major sporting events, these tools also introduce risks that many users may underestimate. In light of this, Kaspersky has shared the key risks fans should keep in mind when using generative AI tools, so they can continue enjoying the championship with peace of mind.

When fan AI goes rogue. A growing number of AI tools are being used to create World Cup-themed visuals, avatars, memes and other fan content. While these services may seem creative and harmless, not all of them come from trusted providers.

Many are launched quickly to capitalise on interest around major events, increasing the likelihood that users will interact with platforms that offer limited transparency around data handling, lack adequate privacy and security measures, or might even be designed with malicious intent.

Personal data at stake. To create customised World Cup content, users are often asked to upload selfies, sign up with an email address, connect social media accounts or share other personal information. In doing so, they may reveal more information than necessary without fully understanding how that data will be stored, used, or potentially exposed.

Advertisement

“AI-driven fan content may seem harmless, but one of the key privacy risks is that users are often encouraged to share far more personal information than necessary. A simple request to generate a themed avatar can involve the collection of photos, contact details, account data and behavioural insights – information that may later be insufficiently protected.

“Because major global events often create an ideal environment for opportunistic actors, fans should take a closer look at how these tools manage personal data before engaging with them,” says Anna Larkina, web content analysis and privacy expert at Kaspersky.

When fan content becomes a scam. AI-generated World Cup content in some cases can also be used to support fraud. Cybercriminals may use convincing mock-ups, fake giveaways, or official-looking fan pages to attract attention and build trust. Once users engage, they may be redirected to phishing sites, fake stores, fraudulent offers, or betting-related scams. Generative AI makes these campaigns easier to produce, more persuasive and far easier to scale.

The myth of AI predictions. Another area that deserves caution is AI-powered match prediction. However advanced or data-driven these tools may appear, AI cannot reliably predict inherently uncertain sporting outcomes. When used to promote betting, paid subscriptions or “insider communities”, such services can create a false sense of confidence and encourage risky decisions.

Advertisement

Kindly share this post
Continue Reading

E-Business

JustMarkets Unveils New Web Terminal That Lets MT5 Traders Skip Software Downloads

Published

on

Kindly share this post

Multi-asset global broker JustMarkets has launched its Web Terminal, an advanced browser-based trading terminal now available to all clients in any country supported by the broker.

JustMarkets Unveils New Web Terminal That Lets MT5 Traders Skip Software Downloads

JustMarkets

The company said the new platform forms part of its ongoing effort to expand and strengthen its trading ecosystem. Before the official launch, the Web Terminal went through a preparation phase during which the team fine-tuned its technical performance and gathered user feedback.

“At JustMarkets, we never stop evolving,” a JustMarkets representative said. “With the Web Terminal, we wanted to remove every barrier between traders and the markets. Now every client can trade directly from their browser, with all the professional tools they need at their fingertips.”

The Web Terminal is fully available for MT5 accounts, allowing traders to access a professional trading environment without downloading or installing any software. The broker said the platform runs entirely in the browser, enabling clients to start trading instantly from any device.

To access the terminal, users are required to choose a trading account, press the “Trade” button, and then select “JustMarkets Terminal” from the window that appears.

The broker said the platform includes advanced charts with technical indicators and graphical tools, flexible volume settings that allow trade volume to be set in lots or in units of the asset, detailed asset descriptions, a market sentiment tool that provides real-time trading sentiment, timely updates on trading schedules and margin changes, and tools for managing multiple trading positions and pending orders.

Advertisement

According to the company, the launch follows the introduction of the JustMarkets mobile app for trading on the go and represents another step in its broader innovation strategy.

JustMarkets said it remains committed to growth and has additional features, tools, and improvements already in development.

Kindly share this post
Continue Reading

Trending