Skip to main content

Nigerian hackers steal $3b worldwide

Nigerian hackers and cyber criminals are being accused of masterminding a grand theft of information and money running into billions of dollars, worldwide.

According to experts, the Nigerians are able to carry out the heist by sending phishing emails to commercial organizations and industrial enterprises, which they later steal dry.

The FBI estimates that these phishing attacks have cost companies over $3 billion. The number of affected companies exceeds 22,143.

Kaspersky Labs, an internet security company said it has found over 500 companies that are under attack in at least 50 countries.

Those under attack are mostly industrial enterprises and large transportation and logistics corporations, based in Germany, UAE, Russia and India.

In a blog post, Kaspersky said the cyber-criminals managed to steal technical drawings, floor plans and diagrams showing the structure of electrical and information networks.

Researchers said that all indications are that these were business email compromise (BEC) attacks that have come to be associated with Nigerian cyber-criminals.

Emails received by victims looked authentic enough to fool people. Some had attachments with names such as “Energy & Industrial Solutions W.L.L_pdf”, “Woodeck Specifications best Prices Quote.uue” and “Saudi Aramco Quotation Request for October 2016”.

These are well crafted emails that look legitimate and are crafted to make the victim open the malicious attachment.

The emails ask the recipients to check information as soon as possible, clarify product pricing or receive goods specified in the delivery note attached. The malicious attachments contain RTF files with an exploit for the CVE-2015-1641 vulnerability.

They may also contain archives of different formats containing malicious executable files or macros and OLE objects designed to download malicious executable files.

Kaspersky discovered that the malicious files are intended to steal confidential data and install stealthy remote administration tools on infected systems.

Using Whois services, Kaspersky found that the domains used to host the malware were registered to residents of Nigeria. Once in, the hackers compromise a legitimate email and change the banking account details.

The malware used in these attacks belonged to families that are popular among cyber-criminals, such as ZeuS, Pony/FareIT, LokiBot, Luminosity RAT, NetWire RAT, HawkEye, ISR Stealer and iSpy keylogger.

”The phishers selected a toolset that included the functionality they needed, choosing from malware available on cyber-criminal forums. At the same time, the malware was packed using VB and .NET packers – a distinct feature of this campaign. To evade detection by security tools, the malicious files were regularly repacked using new modifications of the same packers,” said the researchers.

At least eight different Trojan-Spy and Backdoor families were used in the attacks.

Further research found that the domain names of some of the malware command-and-control servers used by the attackers mimicked domain names used by industrial companies – “more proof that the attacks were primarily targeting industrial companies,” said researchers.

They added that most domains used for malware C&C servers were registered to residents of Nigeria.

Researchers warned that it would be very dangerous if, because of an infection, cyber-criminals were able to gain access to computers that are part of an industrial control system (ICS). “In such cases, they can gain remote access to the ICS and unauthorised control over industrial processes,” said researchers.

Owen Connolly, vice president services (EMEA) at IOActive, told SC Media UK that this attack is not actually targeting industrial control systems or operational technology. “It’s just targeting users that work for large companies. The fact that those companies may also have OT systems could just be coincidence, not correlation,” he said.

Mark James, security specialist at ESET, told SC Media UK that scammers are opportunistic. They understand they need to adapt and will change their tactics to get the best result.

“With the 419 scams being so synonymous with the public, the scope for business users being victims is massive. We also need to consider the scope for larger, single successful attacks reaping the benefits much quicker than the smaller, and often much harder, sells through the public,” he said.

Javvad Malik, security advocate at AlienVault, told SC that organisations dealing with industrial control systems may not be as savvy to scams as financial services, so it could be that the success rate of targeted emails is higher.

“Allowing criminals to make quick money. On the other hand, it could allow criminals to implant malware on industrial control systems, or at least on systems that support the ICS. This can then be allowed for further nefarious purposes such as deploying ransomware – or selling on the access to other criminals or ever nation states,” he said.

Comments

Popular posts from this blog

Kanu Nwankwo: net worth and luxurious assets

It has been five years since the famous  Nigerian  football player Nwankwo Kanu retired, but people are still talking about him. Many want to know what Kanu Nwankwo mansion looks like, or what he is doing now that he is not on the field anymore. However, the most important thing people want to know is the net worth of Kanu Nwankwo. We can satisfy your curiosity, so keep reading to find out about Kanu Nwankwo net worth, as well as a little more on the footballer himself. Who is Nwankwo Kanu? Nwankwo Kanu, known by all as just Kanu or ‘Papilo’, was born in  Owerri ,  Nigeria  on August 1, 1976. His zodiac sign is Leo. His football career lasted for 20 years (1992-2012), and now he is retired and living a happy life. Some quick facts about Kanu: ☛ The name Nwankwo literally means ‘born on the day of Nkwo’ in  Igbo . ☛ During his career, Papilo played for six teams, including Arsenal and Portsmouth, as well as for the...

Naira’s falling value has affected smartphone prices – Revmatas

Revmatas The Director and Business Leader, Information Technology and Mobile, Samsung Electronics West Africa, Mr. Emmanouil Revmatas, speaks to OZIOMA UBABUKOH on innovations adopted by phone companies to sell their brands, among other issues last  year, there was an upheaval in the mobile phone market concerning the Samsung Galaxy Note7, which had battery issues at the time. In what ways has Samsung addressed this? The Galaxy Note7 battery issue led to rigorous efforts to improve quality assurance in Samsung. Samsung examined every aspect of the Galaxy Note7, including hardware, software and related processes over past several months into January 2017. Samsung’s investigation, as well as the investigations completed by three independent industry organisations, concluded that the batteries were the cause of the Galaxy Note7 incidents. These findings informed more rigorous testing and further enhancement of Samsung’s already extremely high level of quality assurance...

10 Things You Need To Know About Nigeria’s Billionaire Kidnappers Evans' ₦3.6Million Vertu Phones

Nigeria’s Billionaire Kidnappers was caught with 2 high tech Phones a Thuraya Phone and a Vertu Phone. First up the thuraya Thuraya’s are satellite telephones, satellite phone, or satphone is a type of mobile phone that connects to orbiting satellites instead of terrestrial cell sites Making it very difficult to track. They provide similar functionality to terrestrial mobile telephones; voice, short messaging service and low-bandwidth internet access are supported through most systems. Now the Vertu Phone which costs over $10k for the cheapest model Continue to see in the next series of pages… 10. The Phone Is Made Of Gold & Its Screen Is Very Durable Not Only Is The Phone Made With Gold, If the phone ever hits the floor, it will surely survive the impact. Because Its 4.7-inch touchscreen is coated with a pricey sheet of sapphire crystal glass, making it nearly impossible to scratch. It can take anything short of a diamond to the screen and remain unscathed,...

Global cyberattack: What you need to know

A massive ransomware attack has hit businesses around the world, causing major companies to shut down their computer systems. Researchers are still investigating the software behind the attack, warning that it is more sophisticated than the WannaCry worm that struck hundreds of thousands of computers across the globe last month. “WannaCry was a tremendous failure. It was a lot of noise, very little money, and everyone noticed it,” said Craig Williams, an expert at cybersecurity firm Cisco Talos. “What we’re seeing today is a much more intelligent worm.” Big global brands like Mondelez (MDLZ), the maker of Oreos, and British advertising giant WPP (WPPGF) and Maersk Group, say their IT systems are experiencing problems. Europol warned Wednesday that there’s still not a “kill switch” able to disable the bug. The ransomware infects computers and locks down their hard drives. It demands a $300 ransom in the anonymous digital currency Bitc...

"I Paid My Own Bride Price," Says Actress Tonto Dikeh

In a leaked chat between Tonto Dikeh and her mother-in-law, the actress revealed she paid for her own bride price. According to her, Quote “Thinking back and after talking to Bimbo Coker, it’s safe to say you are in on Kunle’s fraud and dirty lifestyle Flew your son, clothed him, gave him pocket money, helped him with every sweat in my body, you watched your son dupe me for all my hard earned money.  She went on to reveal even his ex-wife paid for her own wedding. “You disappoint me even Bimbo Coker paid for her own wedding and bride price. Is this a curse?“ This comes after Lara Olubo an OAP who is also a niece of Olakunle Churchill’s mother released a message between Tonto and her mother-in-law. Meanwhile, Churchill’s first wife Bimbo commented on Lara’s post saying that her ex-husband family are all liars. Quote “Smh, this people will never stop lying or even change from their evil ways… soon I know your can of ...

Nigerian Police Say Rate Of Kidnapping Has Dropped Since The Arrest Of Evans 

The rate of kidnapping has dropped following the arrest of Chukwudumeme Onwuamadike (a.k.a Evans), police said at the weekend. Police spokesman Moshood Jimoh, who spoke with The Nation in Abuja, said the International Police (Interpol) was investigating Evans’ activities. “Rate Of Kidnapping Has Dropped Since The Arrest Of Evans”; Police Spokesman He said: “When we paraded him (Evans) in Lagos, I told the public that the arrest of Evans marked the beginning of the end for kidnapping. “Since that day, the rate of kidnapping has seriously gone down and that shows that we were able to hit the right target. “As for keeping him (in custody), we have been able to secure three months’ remand warrant from the Federal High Court, Abuja to enable us round off our investigations. “At present, the contacts and crimes he committed in other countries, including Ghana and South Africa, are of interest. “We have series of complaints that borde...

9 Nollywood Films We Were Blessed With In The 90s

These films are classics. They dominated the 90s & represented what Nollywood was about LIVING IN BONDAGE Year of Release : 1992 Director:  Chris Obi Rapu Cast : Kanayo O. Kanayo, Francis Agu, Kenneth Okonkwo, Ngozi Nwosu, Daniel Oluigbo Trivia : This film was shot with the sum of one hundred and fifty thousand Naira but had made about twenty million soon after its release. Generally regarded as the first Nigerian hit film, Living in Bondage tells the story of Andy Okeke, businessman whose dealings with a money-cult leads to the ritual killing of his wife. It does not take too long before her ghost begins to haunt him and his wealth is short-lived. GLAMOUR GIRLS Year of Release:  1994 Director : Kenneth Nnebue Cast:  Liz Benson, Zack Orji, Keppy Ekpeyong, Sola Fosudo, Ernest Obi, Gloria Anozie, Sandra Achums, Jennifer Okeke, Eucharia Anunobi Trivia:  Zack Orji was suspended by his church for his role in this film. In a scene, he is seen fondling ...

Fish eaters report less arthritis pain

Eating fish at least twice a week may significantly reduce the pain and swelling associated with rheumatoid arthritis, a new study says. PHOTO: yepspokane.com • Regular intake of vegetable protein protects against early menopause Eating fish at least twice a week may significantly reduce the pain and swelling associated with rheumatoid arthritis, a new study says. Prior studies have shown a beneficial effect of fish oil supplements on rheumatoid arthritis symptoms, but less is known about the value of eating fish containing omega-3, the researchers said. “We wanted to investigate whether eating fish as a whole food would have a similar kind of effect as the omega 3 fatty acid supplements,” said the study author, Dr. Sara Tedeschi, an associate physician of rheumatology, immunology and allergy at Brigham and Women’s Hospital in Boston, United States. The findings were reported June 21 in Arthritis Care & Research. Generally, the amount of omega 3 fatty ac...

Revealed: How Evans Was Arrested Through Statements by His Sister and Friend

More details have emerged showing how the notorious kidnapper, Evans was arrested through statements by his sister and friend.  Evans According to a report by Punch Metro, the police have said that useful statements made by a younger sister of the notorious kidnap kingpin, Chukwudi Onuamadike aka Evans, led to his arrest. The sister was said to have been arrested after her number was identified as one of the contacts in Evans’ special SIM card. Punch Metro reports that Evans’ childhood friend and four girlfriends were also picked up by the police and they all gave relevant information. This is just as operatives disclosed that Evans used three phones – two of which reportedly cost N2.4m and N2.6m respectively – with anti-tracking features to frustrate his arrest. It was learnt that he contacted families of his victims through the phones to demand ransoms, bearing in mind that the families could report to the police for tracking. Reliable police sourc...

'I want to die now; this embarrassment is too much'- Evans

Billionaire kidnap kingpin Evans wishes he could just die at the moment as the humiliation is too much for him to bear after falling from grace to grass. Evans has become a cry baby after his arrest  (The Nation) Billionaire kidnapping kingpin,  Chukwudi Dememe Onwuamadike , aka  Evans , says he is tired of life and would not mind sleeping and not waking up the next day  because of the embarrassment and humiliation  he has been made to go through since he was arrested. Evans who was nabbed in his palatial mansion in the Magodo Phase II GRA in the Shangisha area of Lagos State on June 10, 2017, by operatives of the Inspector General of Police Intelligence Response Team [IRT], told the Vanguard that he can't stand the humiliation again and wishes to die. An emotional Evans who is said to weep most of the time inside his cell narrated that he had seen it all,  tasted untold affluence  and there is nothing for him to live for especially as has been di...