Skip to content

Beware: ‘FluBot’ malware targets Nigerians’ Android devices to steal financial data

Beware: 'FluBot' malware targets Nigerians' Android devices to steal financial data

The Nigerian Communications Commission (NCC) has warned the public of a new malware designed to steal credit card and online banking details from devices.

In a press statement released on Friday, the NCC alerted telecom consumers about the ‘FluBot’ malware, which the Nigeria Computer Emergency Response Team (ngCERT) reported to be targeting Android devices.

How the ‘FluBot’ malware works

NCC director of public affairs Ikechukwu Adinde said that ‘FluBot’ impersonates mobile banking apps to steal people’s personal and financial data, and may also pretend to be a FedEx, DHL, Correos, or Chrome application.

The malware, which is being circulated through SMS, can snoop on the phone’s incoming notifications, initiate calls, read and write text messages and transmit the contact list in the device to its control center. 

“The new malware undermines the security of devices by copying fake login screens of prominent banks, and the moment the users enter their login details on the fake pages, their data is harvested and transmitted to the malware operators’ control point from where the data is exploited by intercepting banking-related One Time Passwords (OTPs) and replacing the default SMS app on the targeted Android device,” the  NCC statement read, according to The Cable. <…> “Consequently, it secures admittance into the device through SMS and proceeds to transmit similar messages to other contacts that may be on the device it has attacked enticing them into downloading the fake app.”

The NCC added that the malware compels phone users to change the accessibility settings on their devices. It may also create a backdoor that will give its creators access to compromised devices, further enabling them to commit other illicit acts such as launching new variants of the malware. 

Security tips

The commission advised the public to observe precautions when using their devices. It warned users not to click links from suspicious text messages.

Phone users are also encouraged to have updated antivirus software, use strong passwords and enable two-factor authentication logins, as well as apply critical patches to their systems. 

Those whose phones have already been compromised by the malware can reset their devices to factory setting and change the passwords they use in their online accounts. 

[coinbase]

Best Crypto Exchange for Intermediate Traders and Investors

  • Invest in 70+ cryptocurrencies and 3,000+ other assets including stocks and precious metals.

  • 0% commission on stocks - buy in bulk or just a fraction from as little as $10.

  • Copy top-performing traders in real time, automatically.

  • Regulated by financial authorities including FCA and FINRA.

2.8 Million Users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. eToro USA LLC does not offer CFDs, only real Crypto assets available. Don’t invest unless you’re prepared to lose all the money you invest.

Read Next:

Weekly Finance Digest

By subscribing you agree with Finbold T&C’s & Privacy Policy

Related posts