News

TikTok Challenge Used To Circulate Information-Stealing Malware – NCC

The Nigerian Communications Commission’s Computer Security Incident Response Team (NCC-CSIRT) has warned about the potential harm of taking part in the Invisible Challenge on short-form video hosting service, TokTok, revealing that it exposes devices to Information-Stealing Malware.

An NCC-CSIRT advisory said threat actors have taken advantage of a viral TikTok challenge, known as the Invisible Challenge, to disseminate an information-stealing malware known as the WASP (or W4SP) stealer.

The WASP stealer, which is high in probability with critical damage potential, is a persistent malware hosted on discord that its developer claim is undetectable.

The advisory said “The Invisible Challenge involves wrapping a somewhat transparent body contouring filter around a presumed naked individual. Attackers are uploading videos to TikTok with a link to software that they claim can reverse the filter’s effects.

“Those who click on the link and attempt to download the software, known as “unfilter,” are infected with the WASP stealer. Suspended accounts had amassed over a million views after initially posting the videos with a link. Following the link leads to the “Space Unfilter” Discord server, which had 32,000 members at its peak but has since been removed by its creators.

“Successful installation will allow the malware to harvest keystrokes, screenshots, network activity, and other information from devices where it is installed. It may also covertly monitor user behaviour and harvest Personally Identifiable Information (PII), including names and passwords, keystrokes from emails, chat programs, websites visited, and financial activity. This malware may be capable of covertly collecting screenshots, video recordings, or the ability to activate any connected camera or microphone,” it explained.

The Team said some ways to forestall such an attack include avoiding clicking on suspicious links, using anti-malware software on your devices, checking app tray and removing any apps that you do not remember installing or that are dormant and embracing healthy password hygiene practices such as using a password manager.

The CSIRT is the telecom sector’s cyber security incidence centre set up by the NCC to focus on incidents in the telecom sector and as they may affect telecom consumers and citizens at large.

The CSIRT also works collaboratively with Nigerian Computer Emergency Response Team (ngCERT), established by the Federal Government to reduce the volume of future computer risk incidents by preparing, protecting, and securing Nigerian cyberspace to forestall attacks, and problems or related events.

TruetellsNigeria

Recent Posts

CREDICORP Kicks Off “S.C.A.L.E.” Programme, Channeling Consumer Credit Beneficiaries to Local Vendors and Manufacturers

    The Nigerian Consumer Credit Corporation (CREDICORP) has kicked off its Project S.C.A.L.E. (Securing…

18 minutes ago

Wema Bank Unveils Top 35 Innovators Advancing to the Grand Finale Pitch of Hackaholics 5.0

  Wema Bank, Nigeria's innovative leader in banking and pioneer of Africa’s first fully digital…

23 hours ago

Banana Island aglow with Glo sponsored Starlight Night

The highbrow Banana Island in Ikoyi, Lagos, was literally transformed on Saturday night as Globacom joined the…

23 hours ago

‘No Disparity,’ NUPRC Confirmed 1.8m bopd NNPC Ltd Oil Production Figures At NAPE Conference

    '1.54m bopd production figure (quoted by THISDAY for October) is for September, not…

1 day ago

Lagos 2025 Budget Scales Second Reading

  The Lagos State House of Assembly on Monday debated the 2025 appropriation bill of…

1 day ago

70k minimum Wage Is Unrealistic For Ekiti Workers, Says Otunba Fayose

  A governorship hopeful in Ekiti State, Otunba Emmanuel Fayose has carpeted Governor Biodun Oyebanji…

1 day ago