ICT

Cyberstalking/Crime: Group Plotting to Hack into Businesses/Individuals Networks

 By Mohammed Mohamed

The Nigerian Communications Commission (NCC), has raised the alarm that a cybercrime group has perfected a new year scheme to deliver ransomware to targeted organizations and individual networks.

The new ransomware uncovered by security experts has been categorised, by the Nigerian Computer Emergency Response Team’s (ngCERT) advisory released over the weekend, as high-risk and critical, NCC further hinted.

According to the advisory, the criminal group is said to have been mailing out USB thumb drives to many organisations in the hope that recipients will plug them into their PCs and install the ransomware on their networks. While businesses are being targeted, criminals could soon begin sending infected USB drives to individuals.

Describing how the cybercrime group runs the ransomeware, the ngCERT advisory says the USB drives contain so-called ‘BadUSB’ attacks. The BadUSB exploits the USB standards versatility and allows an attacker to reprogram a USB drive to emulate a keyboard to create keystrokes and commands on a computer. It then installs malware prior to the operating system booting, or spoofs a network card to redirect traffic.

Numerous attack tools are also installed in the process that allows for exploitation of personal computers (PCs), lateral movement across a network, and installation of additional malware. The tools were used to deploy multiple ransomware strains, including BlackBatter and REvil.

According to ngCERT, the attack has been seen in the United States (US), where the USB drives were sent in the mail through the Postal Service and Parcel Service (USPS).

One type contained a message impersonating the US Department of Health and Human Services and claimed to be a COVID-19 warning. Other malicious USBs were sent in the post with a gift card claiming to be from Amazon. 

 However, ngCERT has offered recommendations that will enable corporate and individual networks to mitigate the impact of this new cyberattack and be protected from the ransomware.

These recommendations include a call on individuals and organisations not to insert USB drives from unknown sources, even if they’re addressed to you or your organization.

In addition, if the USB drive comes from a company or a person one is not familiar with and trusts, it is recommended that one contacts the source to confirm they actually sent the USB drive.

Finally, ngCERT has advised Information and Communication Technology as well as other Internet users to report any incident of system compromises to ngCERT via incident@cert.gov.ng, for technical assistance.

Related Posts

Buhari Appoints Tukur Funtua, Bua Cement Staff MD NIGCOMSAT

Faith Maji's NewsHub

Safety of Nigerians in Cyberspace: NCC Outlines Guards against Vulnerabilities

Faith Maji's NewsHub

NITDA Boss Advocates for Development of Int’l Cyber-norms

Faith Maji's NewsHub

NITDA Boss: With Gender Parity, Nigeria ‘ll Rake in $299billion to GDP in 2025

Faith Maji's NewsHub

FEC Approves Nigeria Data Protection Bill

Faith Maji's NewsHub

Tech4Dev: Microsoft Trains 18,000 Nigerian Youths on Free Digital Skills

Faith Maji's NewsHub

NITDA Boss Harps on PPP Initiative as Catalyst to Nigeria’s Digital Economy Drive

Faith Maji's NewsHub

FG Insists Code of Practice ‘ll Improve Content Moderation, Online Safety

Faith Maji's NewsHub

NCC Upscales, Tasks ICT Journalists on Dizzying Speed of Telcos’s Growth

Faith Maji's NewsHub

Leave a Comment

* By using this form you agree with the storage and handling of your data by this website.

Faith Maji's NewsHub
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.