The Nigeria Computer Emergency Response Team (ngCERT) has issued a high-alert warning about a new Android malware campaign called Tria Stealer that targets WhatsApp and Telegram accounts while also intercepting One-Time Passwords (OTPs) and stealing sensitive personal and financial data. The latest threat emerges amid Nigeria’s ongoing efforts to secure its digital infrastructure, including the recent launch of its NINAuth digital identity verification platform.
The malware primarily spreads through deceptive tactics, including fake event invitations distributed via popular messaging platforms. Users are prompted to download an infected Android Package Kit (APK) file that masquerades as a legitimate system application to avoid detection. The distribution method mirrors recent campaigns like FayboyPanel, which similarly targeted mobile banking users through fraudulent applications.
Upon installation, Tria Stealer requests extensive device permissions, including access to SMS messages, call logs, and app notifications. The malware immediately begins harvesting data and transmitting stolen information to a Command and Control server operated through Telegram bots, similar to the recently discovered FireScam malware that also exploited Telegram’s infrastructure.
The malware’s capabilities include intercepting OTPs used in banking authentication, initiating fraudulent money transfers using victim identities, accessing financial and banking applications without authorization, stealing login credentials, and installing additional malicious payloads without user consent. The attack vector is particularly concerning as many financial institutions are moving away from SMS-based authentication, with major platforms like Google planning to end SMS verification due to security vulnerabilities.
Tria Stealer’s distribution method involves sending fraudulent APK files disguised as wedding or event invitations through chat messages. Users who believe these to be legitimate proceed to install the compromised applications. The approach exploits the growing reliance on messaging apps for communication, despite both WhatsApp and Telegram having recently implemented enhanced security features, including biometric authentication options.
NgCERT has issued several security recommendations to combat this threat. Users are advised to avoid downloading APK files from untrusted sources, especially through messaging apps. The agency emphasizes careful review of app permissions before installation, particularly those requesting access to sensitive functions like SMS and call logs.
Additional protective measures include maintaining up-to-date antivirus software, though Tria Stealer employs encryption and obfuscation techniques to evade detection. Regular device updates are recommended to patch known vulnerabilities, and users should use end-to-end encrypted messaging applications that offer greater resistance to malware hijacking. These recommendations match recent CISA guidelines on mobile security, which emphasize the importance of encryption and strong authentication methods.
Sources: BusinessDay.ng, Nairametrics, Legit.ng, Techeconomy.ng, National Daily