" ITREALMS: malware
Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Tuesday, December 10, 2024

Most Wanted Malware: Androxgh0st, targets IoT devices, critical infrastructure - ITREALMS

ITREALMS ... making leadership SENSE with digital news!

The Check Point Software's latest threat index for November 2024 has highlighted the rise of Androxgh0st, a Mozi-integrated botnet, and ongoing threats from Joker and Anubis, showcasing evolving cybercriminal tactics, reports ITREALMS.
Most Wanted Malware: Androxgh0st, targets IoT devices, critical infrastructure - ITREALMS
This is coming as Seven African countries are among the top 20 most attacked.

Sunday, March 26, 2023

NCC-CSIRT: Beware of pirated YouTube software-related Malware - ITREALMS

ITREALMS ... making leadership SENSE with digital news!

The Computer Security Incident Response Team (NCC-CSIRT) of the Nigerian Communications Commission (NCC) has warned those looking to acquire pirated software and resources that they risk becoming victims of cybercriminal gangs that are using AI-generated YouTube videos to distribute malware, reports 
ITREALMS.
NCC-CSIRT: Beware of pirated YouTube software-related Malware - ITREALMS
Also, NCC-CSIRT warned in its advisory that the consequences of falling victim can be significant for individuals and organizations, resulting in critical damage like data theft, financial loss, identity theft, system damage, and reputation damage.

Wednesday, December 07, 2022

Beware! TikTok challenge circulates information-stealing Malware says NCC - ITREALMS

ITREALMS ... making leadership SENSE with digital news!


The Nigerian Communications Commission's Computer Security Incident Response Team (NCC-CSIRT) has warned about the potential harm of taking part in the Invisible Challenge on short-form video hosting service, TikTok, revealing that it exposes devices to information-stealing Malware.
An NCC-CSIRT advisory said threat actors have taken advantage of a viral TikTok challenge, known as the Invisible Challenge, to disseminate an information-stealing malware known as the WASP (or W4SP) stealer.

Monday, August 08, 2022

Privacy: NCC-CSIRT flags ‘HiddenAds’ malware - ITREALMS

PressRelease@ITREALMS ... making leadership SENSE with digital news!

The Nigerian Communications Commission's Computer Security Incident Response Team (NCC-CSIRT) has flagged a new malware, HiddenAds, which has infiltrated Google Play Store that can impact device performance and jeopardize users’ privacy.

In its advisory of August 8, 2022, NCC-CSIRT classified the virus, first identified by the McAfee Mobile Research Team, as high in probability and damage potential.

Friday, August 06, 2021

29% of corporate users experienced financial malware attacks, first half of 2021 - ITREALMS

ITREALMS ... making leadership SENSE with digital news!

Latest Kaspersky report has shown that some 29 per cent of corporate users experience financial malware attacks in the first half of 2021, reports 
ITREALMS.
They also said that this is particular in Kenya, their Kaspersky research showed that the overall number of financial malware attacks in Kenya has decreased in the first half of 2021, when compared to the same period in 2020, 29.3% of the 7 962 attacks recorded in the country targeted corporate users, which is a cause for concern, warn Kaspersky experts.

Tuesday, March 13, 2018

Africa & Middle East: Slingshot malware on spy rampage

The Kaspersky Lab researchers have uncovered a sophisticated threat across 11 countries, used for cyber-espionage in the Middle East and Africa from at least 2012 until February 2018, reports ITRealms.

The malware, ITRealms gathered is called ‘Slingshot’, which attacks and infects victims through compromised routers and can run in kernel mode, giving it complete control over victim devices.
These countries, ITRealms also gathered  included Kenya, Yemen, Afghanistan, Libya, Congo, Jordan, Turkey, Iraq, Sudan, Somalia and Tanzania have been listed among the 100 victims worldwide.

According to researchers, many of the techniques used by this threat actor are unique and it is extremely effective at stealthy information gathering, hiding its traffic in marked data packets that it can intercept without trace from everyday communications.

The Slingshot operation was discovered after researchers found a suspicious keylogger program and created a behavioural detection signature to see if that code appeared anywhere else. This triggered a detection that turned out to be an infected computer with a suspicious file inside the system folder named scesrv.dll.

In addition, the researchers decided to investigate this further, just as analysts are of the view that the file showed that despite appearing legitimate, the scesrv.dll module had malicious code embedded into it. Since this library is loaded by ‘services.exe’, a process that has system privileges, the poisoned library gained the same rights. The researchers realised that a highly advanced intruder had found its way into the very core of the computer.

The most remarkable thing about Slingshot is probably its unusual attack vector. As researchers uncovered more victims, they found that many seemed to have been initially infected through hacked routers. During these attacks, the group behind Slingshot appears to compromise the routers and place a malicious dynamic link library inside it that is in fact a downloader for other malicious components.


When an administrator logs in to configure the router, the router’s management software downloads and runs the malicious module on the administrator’s computer. The method used to hack the routers in the first place remains unknown.

Chuks Egbune/GEE

ITREALMS ... everything news digitally!