InsightLinks See the story clearly
Explore News Politics Sports Crime and Metro Local News Entertainment Uncategorized World News Education Osun News
News

NCC raises the alarm over SMS-based virus that takes over Android devices

  The Nigerian Communications Commission (NCC) has warned of a new high-risk, critical and Short Messaging Service (SMS)-based malware, TangleBot, infecting Android mobile devices. TangleBot, according to the agency, employs more or…

 

The Nigerian Communications Commission (NCC) has warned of a new high-risk, critical and Short Messaging Service (SMS)-based malware, TangleBot, infecting Android mobile devices.

TangleBot, according to the agency, employs more or less similar tactics as the recently-announced notorious FlutBot SMS Android malware that targets mobile devices.

It warned TangleBot also gains control of the device but in far more invasive manner than the FlutBot malware.

This was disclosed in a security advisory made available to the Commission’s New Media and Information Security Department by the Nigerian Computer Emergency Response Team (ngCERT).

It said: “TangleBot Android malware is installed when an unsuspecting user clicks on a malicious link disguised as COVID-19 vaccination appointment-related information in an SMS message or information about fake local power outages that are due to occur.”

NCC Director, Public Affairs, Dr Ikechukwu Adinde, said the motive behind both or either of the messages (on COVID-19 or impending power outages) is to encourage potential victims to follow a link that supposedly offers detailed information.

“Once at the page, users are asked to update applications such as Adobe Flash Player to view the page’s content by going through nine (9) dialogue boxes to give acceptance to different permissions that will allow the malware operators to initiate the malware configuration process.

“The immediate consequence is that TangleBot gains access to several different permissions when installed on a device, allowing it to eavesdrop on user communications.

“The malware then steals sensitive data stored on the device and monitors almost every user activity, including camera use, audio conversations, and location, among other things.

“Furthermore, the malware takes complete control of the targeted device, including access to banking data, and can reach the deepest recesses of the Android operating system.”

On how to stay safe, the ngCERT suggested “an advisory to telecom consumers and other Internet users to refrain from opening Uniform Resource Locators (URLs) from unknown sources while using your mobile devices.

“Additionally, telecom consumers should never respond or send a reply to messages or call back a phone number that is associated with the text that they are unaware of.

“Should any telecom consumer or Internet user become curious and wish to ascertain the authenticity of any call or messages and wish to probe the incident, such persons may do a web search of both the number and the message content.”

Other risk-mitigating measures advised by ngCERT is for users to be cautious of procuring any software from outside a certified app store. (The Nation)

Advertisement


Story network

Understand the wider story

Connected reporting selected by topic, category and recency.

Continue exploring

Follow the wider story

Discover related reporting, current updates, and the latest stories from InsightLinks.

Latest stories →
Published January 29, 2022
Share Facebook X