Thursday, April 25, 2024

Schoolyard Bully: NCC-CSIRT warns about malware stealing Facebook accounts

NCC-CSIRT said it had infected over 300,000 android devices, prompting an advisory reminding users to download applications from official sites and store applications.

• December 15, 2022
FACEBOOK and NCC
FACEBOOK and NCC

The Nigerian Communications Commission’s Computer Security Incident Response Team (NCC-CSIRT) has warned against a malware attack that steals Facebook account credentials, also known as Schoolyard Bully.

NCC-CSIRT said it had infected over 300,000 android devices, which prompted an advisory reminding users to only download applications from official sites and application stores.

NCC spokesman Reuben Muoka disclosed this in a statement on Wednesday.

Mr Muoka said researchers from mobile security firm, Zimperium, found several apps that transmit the Schoolyard Bully malware, disguised as reading and educational apps.

According to him, the malicious apps were available on Google Play, adding, ”yet they have already been taken down, and they still spread via third-party Android app shops.”

He added, “The NCC-CSIRT advisory in this regard further recommended that users double-check each application and uncheck boxes that request extra third-party downloads when installing apps downloaded from the Google Play Store. And to use anti-malware applications to routinely scan their devices for malware.”

The NCC official explained that the primary objective of the malware, which “affects all versions of Facebook Apps for Android, is to steal Facebook account information” and to steal email address and password, account ID, username, device name, device RAM (Random Access Memory), and device API (Application Programming Interface).

The (Zimperium) research stated that the malware “employs JavaScript injection” to steal Facebook login information and that the malware “loads a legitimate URL (web address) inside a WebView (a WebView maps website elements” that enable user interaction through Android View objects and their extensions) with malicious JavaScript injected.

“To obtain the user’s contact information (phone number, email address, and password), then send it to the command-and-control server,” said NCC-CSIRT. 

He said malware uses native libraries to evade detection and analysis by security software and machine learning technologies.

The CSIRT is the telecom sector’s cybersecurity incidence centre set up by the NCC to focus on incidents in the telecom sector and as they may affect telecom consumers and citizens at large. It works collaboratively with Nigerian Computer Emergency Response Team (ngCERT), established by the federal government.

It was established to “reduce the volume of future computer risk incidents by preparing, protecting, and securing Nigerian cyberspace to forestall attacks, and problems or related events.”

(NAN)

We have recently deactivated our website's comment provider in favour of other channels of distribution and commentary. We encourage you to join the conversation on our stories via our Facebook, Twitter and other social media pages.

More from Peoples Gazette

Katsina State

Politics

Katsina youths pledge to deliver over 2 million votes to Atiku

“Katsina State is Atiku’s political base because it is his second home.”

Zulum and Qatar Ambassador to Nigeria in Maiduguri

Uncategorized

Qatar to sponsor education of 1,000 orphans in Borno

The ambassador of the State of Qatar to Nigeria, Ali-bin Ghanem Al-Hajri, made this known on Thursday in Maiduguri during a courtesy visit to Governor Babagana Zulum of Borno.

FIFA President Gianni Infantino

Sport

FIFA announces multi-year partnership with Saudi-owned oil company Aramco 

The deal with Saudi Arabia-owned Aramco is in effect until 2027, covering the 2026 FIFA World Cup in the U.S., Canada, and Mexico and the Women’s World Cup the following year.

JAMB

Heading 5

Again, JAMB extends 2024 direct entry registration

JAMB announced the commencement of the registration for the 2024 direct entry from February 28 to March 28 but extended it by two weeks, ending April 11.

Seyin Makinde

Ibadan

Oyo government declares Friday half-working for LG polls

The statement indicated that the half working day was in connection with the local government elections, scheduled for Saturday.

Eberechi Eze, Michael Olise

Sport

Crystal Palace want £60 million to sell Eberechi Eze, Michael Olise 

Any deal to sign either player will largely depend on them pushing for a move to a bigger club or Palace receiving tempting offers.

Lagos-Calabar highway

States

FG to begin demolition for first 3km of Lagos-Calabar highway Saturday

The 700km Lagos-Calabar coastal highway project is designed to connect Lagos to Cross River.