Skip to content
July 20, 2026
  • Home
  • About us
  • Contact us
  • Newsletter
  • Privacy Policy
Political Economist

Political Economist

A liberal News reporting Politics, Sports, Business, Commentaries

  • Home
  • National News
    • Metro News
      • metro
    • Society
    • Crime and Justice
  • Special Reports
    • Investigation
    • Features
    • Interviews
  • Opinion
    • Commentaries
    • Perspectives
  • Press Releases
  • International News
  • Business & Economy
  • Politics
Watch Online
  • Home
  • Business & Economy
  • Another malware, Xenomorph breaks out; NCC-CSIRT advises factory-resetting infected devices
  • Business & Economy

Another malware, Xenomorph breaks out; NCC-CSIRT advises factory-resetting infected devices

Admin December 7, 2022
Hackers

NCC logo

Hackers
NCC logo

A malware, Xenomorph, that installs Trojan in banking apps on the Android platform to steal login details, raid bank accounts,  and read the users SMS, has been flagged by the Nigerian Communications Commission’s Computer Security Incident Response Team (NCC-CSIRT).

The Team suggests that owners of compromised devices take the extreme measure of doing factory resetting of infected devices.

NCC-CSIRT, citing Zscaler ThreatLabz, said, “The Todo: Day Manager hijacks your login info from banking apps, and can even read your SMS messages. It installs a banking trojan malware called Xenomorph that allows the app to intercept your two-factor verification codes (typically delivered over text) to raid your logins – and bank account.

“Xenomorph performs overlay attacks by exploiting accessibility permissions in Android, resulting in the overlaying of fraudulent login screens on banking apps aimed at exfiltrating credentials. The Android app makes itself intentionally difficult to delete. You need to search your phone for it immediately and uninstall it.”

“It starts with asking users to enable access permission. Once provided, it adds itself as a device admin and prevents users from disabling Device Admin, making it un-installable from the phone.  If you haven’t given permission to the app, then you should be able to uninstall it safely. Otherwise, you may have to back up your files and then factory-reset your phone to clear the app completely,” it advised.

In terms of potential solutions to the malware, NCC-CSIRT advised that “Search your phone for the app and uninstall immediately or backup your files and factory reset your phone.

“Only search for an app in the Google Play Store, pay close attention to the search results, look at the apps icons, note that fake apps almost always use the icon from the app they’re faking, then look at the developer’s name and make sure it’s from the right developer.

Also, look at the app’s download count. If the app has a lot of downloads going into millions to hundreds of thousand that’s a clue that it’s the right app.  Then, finally, look at the app’s description and screenshots to ensure that it doesn’t contain multiple spelling or grammar mistakes or otherwise broken English.

“Make use of Google Play Protect, which regularly scans your apps for malware and will alert you to uninstall rogue apps.”

The CSIRT is the telecom sector’s cyber security incidence centre set up by the NCC to focus on incidents in the telecom sector and as they may affect telecom consumers and citizens at large.

The CSIRT also works collaboratively with Nigeria Cybersecurity Emergency Response Team (ngCERT), established by the Federal Government to reduce the volume of future computer risk incidents by preparing, protecting, and securing Nigerian cyberspace to forestall attacks, and problems or related events.

  • Facebook
  • Share on X
  • LinkedIn
  • WhatsApp
  • Email
  • Copy Link
Tags: Banking apps Malware NCC-CSIRT ngCERT Xenomorph Zscaler ThreatLabz

Post navigation

Previous EFCC Conducts Public Auction of Over 400 Cars in Lagos
Next N-POWER: DBANJ ENCOURAGES ICPC TO DO ITS INVESTIGATION, CAUTIONS AGAINST MEDIA TRIAL 

Related Stories

Fuel price uncertainty forces marketers to temporarily halt supply — IPMAN Fuel crisis
  • Business & Economy

Fuel price uncertainty forces marketers to temporarily halt supply — IPMAN

July 19, 2026
Oborevwori unveils digital advertising platform to boost Delta revenue
  • Business & Economy

Oborevwori unveils digital advertising platform to boost Delta revenue

July 18, 2026
Global energy security at risk if Strait of Hormuz does not open in weeks, IEA chief says IEA
  • Business & Economy

Global energy security at risk if Strait of Hormuz does not open in weeks, IEA chief says

July 17, 2026
logo

Political Economist is a liberal news magazine with global affiliations.

At Political Economist, we promote free enterprise and act as a catalyst for the growth of knowledge economy. We are proudly pan-Nigeria yet richly spiced with African and global news. We offer a fair and balanced news reportage presented by our team of well-heeled professional journalists. <

About us

  • 5 Olutosin Ajayi Street, By CPM Church, Ajao Estate, Lagos State, Nigeria
  • +234 805 680 1124
  • info@politicaleconomistng.com

Follow

Subscribe to notifications

You may have missed

Fuel price uncertainty forces marketers to temporarily halt supply — IPMAN Fuel crisis
  • Business & Economy

Fuel price uncertainty forces marketers to temporarily halt supply — IPMAN

July 19, 2026
Oyo mandates birth certificates, NIN for school enrolment — Perm Sec oyo
  • National News

Oyo mandates birth certificates, NIN for school enrolment — Perm Sec

July 19, 2026
NDLEA intercepts Kano-bound tramadol shipments, arrests 80-year-old grandpa
  • Crime and Justice

NDLEA intercepts Kano-bound tramadol shipments, arrests 80-year-old grandpa

July 19, 2026
Troops foil ISWAP mass abduction bid, rescue 46 students in Borno Troops
  • National News

Troops foil ISWAP mass abduction bid, rescue 46 students in Borno

July 19, 2026
  • Home
  • About us
  • Contact us
  • Newsletter
  • Privacy Policy
Copyright © All rights reserved. | DarkNews by AF themes.