Thursday, April 18, 2024

NCC uncovers hackers’ new ploy to unlock, steal vehicles in Nigeria

The NCC advised car owners in these categories to choose Passive Keyless Entry (PKE) as opposed to Remote Keyless Entry (RKE).

• May 15, 2022
Carjacking
Carjacking used to illustrate the story [Photo Credit: Sydney Criminal Lawyer]

The Nigerian Communications Commission (NCC) has alerted telecom consumers and public members on an ongoing cyber-vulnerability that allows a nearby hacker to unlock vehicles, start their engines wirelessly, and make away with them.

This is contained in the latest advisory released by the Computer Security Incident Response Team (CSIRT) established by the NCC and shared by the commission’s spokesperson, Ikechukwu Adinde.

“The fact that car remotes were categorised as short-range devices that use Radio Frequency (RF) to lock and unlock cars informed the need to alert Nigerians on this emergent danger.

“The vulnerability is a Man-in-the-Middle (MitM) attack or, more specifically, a replay attack in which an attacker intercepts the RF signals normally sent from a remote key fob to the car.

“It manipulates these signals and resends them later to unlock the car at will,” it stated.

The advisory stated that the latest cyber-attack gives room for easy manipulation of captured commands and re-transmitting them to achieve a different outcome altogether.

The commission’s spokesperson, however, said that the NCC-CSIRT, in the advisory, had offered some preventive measures or solutions that car owners could adopt to prevent falling victim.

According to the cyber-alert unit of the commission, when affected, the only mitigation is to reset your key fob at the dealership.

“Additionally, vulnerable car users should store their key fobs in signal-blocking ‘Faraday pouches’ when not in use.”

He advised car owners in these categories to choose Passive Keyless Entry (PKE) as opposed to Remote Keyless Entry (RKE), which would make it harder for an attacker to read the signal because criminals would need to be at close range to carry out their nefarious acts.

In a related advisory, he said that the NCC, based on another detection by CSIRT, wishes to inform the general public about the resurgence of Joker Trojan-Infected Android Apps on the Google Play Store.

“This arose due to the activities of criminals who intentionally download legitimate apps from the Play Store, modify them by embedding the Trojan malware and then upload the app back to the Play Store with a new name.

“The malicious payload is only activated once the apps go live on the Play Store, enabling the apps to scale through Google’s strict evaluation process.”

According to the advisory, the apps request for permissions and once granted, have access to critical functions.

“As a consequence, a compromised device will subscribe unwitting users to premium services, billing them for services that do not exist. A device like this can also be used to commit Short Messaging Service (SMS) fraud while the owner is unaware,” he said.

Mr Adinde said that the app could click on online ads automatically and even use SMS One-Time Password (OTPs) to approve payments without checking bank statements secretly.

The NCC also advised telecom consumers to ensure that apps installed from the Google Play Store are heavily scrutinised by reading reviews, assessing the developers, perusing the terms of use and only granting the necessary permissions.

(NAN) 

We have recently deactivated our website's comment provider in favour of other channels of distribution and commentary. We encourage you to join the conversation on our stories via our Facebook, Twitter and other social media pages.

More from Peoples Gazette

Katsina State

Politics

Katsina youths pledge to deliver over 2 million votes to Atiku

“Katsina State is Atiku’s political base because it is his second home.”

Bola Tinubu and Nuhu Ribadu

Heading 3

Tinubu’s renewed hope agenda showing positive results in tackling Nigeria’s security challenges: Ribadu

We are not out of the woods yet but we have made serious progress in pushing down casualty figures

GAZA STRIP IN RUINS

World

UN launches $2.8 billion flash appeal for Palestine

“Humanitarian organisations must have safe and sustained access to all people in need across the Gaza Strip and West Bank.”

NAFDAC

Abuja

NAFDAC raids Sahad stores, others in Abuja for allegedly selling counterfeit products

He said the team equally raided Wuse Market on Wednesday, where goods worth millions were seized.

LGBTQ flag

Africa

Botswana churches kick against gay rights proposal

A cleric expressed his disappointment at the development in amending the constitution.

Enugu

Police nab suspected transformer vandal in Enugu

Mr Ndukwe said operatives arrested the 23-year-old suspect at about 5:30 a.m. on April 12