Home NCC-CSIRT warns against new Phishing attack which bypasses security alerts

NCC-CSIRT warns against new Phishing attack which bypasses security alerts

Share
Share
By Chioma Obinagwam
The Nigerian Communications Commission’s Computer Security Incident Response Team (NCC-CSIRT) has warned the public against a new Phishing attack that does not trigger any Windows security alerts.
Confiance News gathered from a statement issued by the Nigeria Communications Commission (NCC) on Saturday.
“Attacks Exploit Windows Zero-Day Vulnerability, can load a malicious QBot malware on the compromised device without triggering any Windows security alerts,” the statement revealed.
In its advisory, NCC-CSIRT indicated that the vulnerability, which is present
 in all versions of Windows-based products, presents as Phishing Attacks and Malware threats.
Confiance News further learnt from Wikipedia, a free online encyclopedia, that phishing is a type of social engineering where an attacker sends a fraudulent (e.g., spoofed, fake, or otherwise deceptive) message designed to trick a person into revealing sensitive information to the attacker or to deploy malicious software on the victim’s infrastructure like ransomware.
NCC-CSIRT reports that ProxyLife security researcher discovered the new phishing exploit on Windows zero-day vulnerability to drop a Qbot malware without displaying Mark of the Web (MoTW) security warnings.
“To take advantage of the Windows Mark of the Web zero-day vulnerability, threat actors have switched to a new phishing strategy that involves propagating JS files (plain text files that include JavaScript code) signed with forged signatures. The newest phishing attempt begins with an email that contains a password for the file along with a link to an allegedly important document.
“When the link is clicked, a password-protected ZIP folder that includes another zip file and an IMG file is downloaded. Normally, launching the JS file in Windows would result in a Mark of the Web security warning because it is an Internet-based file. However, the forged signature permits the JS script to function and load the malicious QBot program without triggering any Windows security alerts,” the advisory said.
Accordingly, NCC-CSIRT advised that users apply updates per vendor instructions.
The CSIRT is the telecom sector’s cyber security incidence centre set up by the NCC to focus on incidents in the telecom sector and as they may affect telecom consumers and citizens at large.
The CSIRT also works collaboratively with ngCERT, established by the Federal Government (FG) to reduce the volume of future computer risk incidents by preparing, protecting, and securing Nigerian cyberspace to forestall attacks, and problems or related events.
Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Member

Don't Miss

Freed but behind: Oyo pupils’ school crisis begins‎

By Chioma Obinagwam‎‎The 46 pupils and teachers freed from captivity in Orire on Friday are coming home to empty desks, a stalled term...

Dangote Cement rating upgraded as profit jumps 109%

By Chioma Obinagwam‎‎Dangote Cement Plc has received a fresh vote of confidence from DataPro, the Technology-Driven Credit Rating Agency, following an upgrade of...

Related Articles

Freed but behind: Oyo pupils’ school crisis begins‎

By Chioma Obinagwam‎‎The 46 pupils and teachers freed from captivity in Orire...

Dangote Cement rating upgraded as profit jumps 109%

By Chioma Obinagwam‎‎Dangote Cement Plc has received a fresh vote of confidence...

NLNG bags Operational Excellence Award at NOG energy week‎

‎By Chioma Obinagwam‎‎Nigeria LNG Limited has clinched the Operational Excellence Award at...

CBN reaffirms ₦100 note remains legal tender

By Chioma Obinagwam The Central Bank of Nigeria (CBN) has moved to...