<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Xenomorph Archives - Tech Digest News</title>
	<atom:link href="https://techdigest.ng/tag/xenomorph/feed/" rel="self" type="application/rss+xml" />
	<link>https://techdigest.ng/tag/xenomorph/</link>
	<description>- Latest Nigeria Tech News Today</description>
	<lastBuildDate>Mon, 28 Feb 2022 17:22:44 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.1</generator>

<image>
	<url>https://techdigest.ng/wp-content/uploads/2024/12/cropped-techdigest-featured-image-32x32.jpg</url>
	<title>Xenomorph Archives - Tech Digest News</title>
	<link>https://techdigest.ng/tag/xenomorph/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">197179539</site>	<item>
		<title>NCC warns against software that steals users’ banking app</title>
		<link>https://techdigest.ng/ncc-warns-software-steals/</link>
		
		<dc:creator><![CDATA[kabir Abdulsalam]]></dc:creator>
		<pubDate>Mon, 28 Feb 2022 17:22:44 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Google play store]]></category>
		<category><![CDATA[Xenomorph]]></category>
		<guid isPermaLink="false">https://techdigest.ng/?p=71837</guid>

					<description><![CDATA[<p>NCC warns against software that steals users’ banking app The Computer Security Incident Response Team (CSIRT) of the Nigerian Communications Commission’s (NCC) says it had discovered a newly-hatched malicious software that steals users’ banking app login credentials on Android devices. NCC’s Director of Public Affairs (DPA), Dr Ikechukwu Adinde, disclosed this in a statement on [&#8230;]</p>
<p>The post <a href="https://techdigest.ng/ncc-warns-software-steals/">NCC warns against software that steals users’ banking app</a> appeared first on <a href="https://techdigest.ng">Tech Digest News</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><strong>NCC warns against software that steals users’ banking app</strong></p>
<p>The Computer Security Incident Response Team (CSIRT) of the<a href="https://www.ncc.gov.ng/" target="_blank" rel="noopener"> Nigerian Communications Commission’s</a> (NCC) says it had discovered a newly-hatched malicious software that steals users’ banking app login credentials on Android devices.</p>
<p>NCC’s Director of Public Affairs (DPA), Dr Ikechukwu Adinde, disclosed this in a statement on Sunday, in Abuja.</p>
<p>Adinde explained that the main intent of this malware was to steal credentials, combined with the use of SMS and notification interception to log-in and use potential two-factor authentication tokens.</p>
<p>He said, according to a security advisory from the NCC CSIRT, the malicious software called “Xenomorph”, found to target 56 financial institutions across Europe, had high impact and high vulnerability rate.</p>
<p>“Xenomorph is propagated by an application that was slipped into Google Play store and masquerading as a legitimate application called “Fast Cleaner” ostensibly meant to clear junk, increase device speed and optimise battery.</p>
<p>“In reality, this app is only a means by which the Xenomorph Trojan could be propagated easily and efficiently.</p>
<p>“Fast Cleaner was disseminated before the malware was placed on the remote server, making it hard for Google to determine that such an app is being used for malicious actions.</p>
<p>“This is to avoid early detection or being denied access to the Playstore,” he said.</p>
<p>He further explained that once up and running on a victim’s device, Xenomorph can harvest device information and SMS, intercept notifications and new SMS, perform overlay attacks and prevent users from uninstalling it.</p>
<p>“The threat also asks for Accessibility Services privileges, which allow it to grant itself further permissions.</p>
<p>“The CSIRT said the malware also steals victims’ banking credentials by overlaying fake login pages on top of legitimate ones.</p>
<p>“Considering that it can also intercept messages and notifications, it allows its operators to bypass SMS-based two-factor authentication and log into the victims’ accounts without alerting them.</p>
<p>“The Fast Cleaner app has now been removed from the Play Store but not before it garnered 50,000+ downloads,” he said.</p>
<p>The DPA said that the commission had advised telecom consumers to be on alert in order not to fall victims of this manipulation.</p>
<p>He urged telecom consumers and other Internet users, particularly those using Android-powered devices, to use trusted Antivirus solutions and update them regularly to their latest definitions.</p>
<p>He also implored consumers and other stakeholders to always update banking applications to their most recent versions.</p>
<p>The News Agency of Nigeria (NAN) reports that Xenomorph has been found to target 28 banking apps from Spain, 12 from Italy, 9 from Belgium, and 7 from Portugal.</p>
<p>Cryptocurrency wallets and general-purpose applications like emailing services are also some of the target.</p>
<p>The Computer Security Incident Response Team (CSIRT) of the Nigerian Communications Commission’s (NCC) says it had discovered a newly-hatched malicious software that steals users’ banking app login credentials on Android devices.</p>
<p>NCC’s Director of Public Affairs (DPA), Dr Ikechukwu Adinde, disclosed this in a statement on Sunday, in Abuja.</p>
<p>Adinde explained that the main intent of this malware was to steal credentials, combined with the use of SMS and notification interception to log-in and use potential two-factor authentication tokens.</p>
<p>Also read:<a title="NCC deploys Revenue Assurance Solution to block revenue leakage" href="https://techdigest.ng/ncc-deploys-revenue-assurance/" rel="bookmark" data-wpel-link="internal">NCC deploys Revenue Assurance Solution to block revenue leakage</a></p>
<p>He said, according to a security advisory from the NCC CSIRT, the malicious software called “Xenomorph”, found to target 56 financial institutions across Europe, had high impact and high vulnerability rate.</p>
<p>“Xenomorph is propagated by an application that was slipped into Google Play store and masquerading as a legitimate application called “Fast Cleaner” ostensibly meant to clear junk, increase device speed and optimise battery.</p>
<p>“In reality, this app is only a means by which the Xenomorph Trojan could be propagated easily and efficiently.</p>
<p>“Fast Cleaner was disseminated before the malware was placed on the remote server, making it hard for Google to determine that such an app is being used for malicious actions.</p>
<p>“This is to avoid early detection or being denied access to the Playstore,” he said.</p>
<p>He further explained that once up and running on a victim’s device, Xenomorph can harvest device information and SMS, intercept notifications and new SMS, perform overlay attacks and prevent users from uninstalling it.</p>
<p>“The threat also asks for Accessibility Services privileges, which allow it to grant itself further permissions.</p>
<p>“The CSIRT said the malware also steals victims’ banking credentials by overlaying fake login pages on top of legitimate ones.</p>
<p>“Considering that it can also intercept messages and notifications, it allows its operators to bypass SMS-based two-factor authentication and log into the victims’ accounts without alerting them.</p>
<p>“The Fast Cleaner app has now been removed from the Play Store but not before it garnered 50,000+ downloads,” he said.</p>
<p>The DPA said that the commission had advised telecom consumers to be on alert in order not to fall victims of this manipulation.</p>
<p>He urged telecom consumers and other Internet users, particularly those using Android-powered devices, to use trusted Antivirus solutions and update them regularly to their latest definitions.</p>
<p>He also implored consumers and other stakeholders to always update banking applications to their most recent versions.</p>
<p>The News Agency of Nigeria (NAN) reports that Xenomorph has been found to target 28 banking apps from Spain, 12 from Italy, 9 from Belgium, and 7 from Portugal.</p>
<p>Cryptocurrency wallets and general-purpose applications like emailing services are also some of the target.</p>
<p>The post <a href="https://techdigest.ng/ncc-warns-software-steals/">NCC warns against software that steals users’ banking app</a> appeared first on <a href="https://techdigest.ng">Tech Digest News</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">71837</post-id>	</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 

Served from: techdigest.ng @ 2026-09-18 10:05:43 by W3 Total Cache
-->