Internet security company ESET East Africa has issued an alert to mobile phone users running on the Android platfom to be wary of alternative app stores’ potential to spread malware such as screen locking malware.
According to Teddy Njoroge, Kenya Country Manager for ESET, ransomware is a fast growing problem for users of mobile devices. “Just like SMS trojans, ransomware threats have evolved over the past few years with hackers adopting techniques that have proven effective in regular desktop malware to develop lock-screen types and file-encrypting ransomware. These have been causing major financial and data losses for years and which have now made their way to the Android platform“, he said.
The alert comes after Cyber-crime researchers at ESET discovered that www.CepKutusu.com, a Turkish alternative Android app store was spreading malware under the guise of all the offered Android apps on the site
When users browsed the Turkish alternative app store CepKutusu.com and proceeded to downloading an app, the “Download now” button led to banking malware detected as Android/Spy.Banker.IE instead of the desired app.
After ESET researchers turned to the store’s operator with the discovery of the attack, the store ceased the malicious activity. ESET Android malware researcher, Lukas Stefanko said this was an entrirely new tactic by cybercrimnals.
“This is the first time I’ve seen an entire Android market infected like that. Within the Windows ecosystem and in browsers, this technique is known to have been used for some time but in the Android ecosystem, it’s really a new attack vector“, he said.
Athough the misdirection on www.CepKutusu.com was from a legitimate app to the malicious banking malware, the crooks behind the campaign added an exception, a tactic commonly used to increase the chances of staying longer under the radar.
The hackers introduced a seven-day window of not serving malware after a malicious download, thus falsely serving the user with clean download links, only to be redirected to the malware once they try to download any application from the store after the period lapses.
Although focused in Turkey and parts of Europe, the incident points to the growing appetite for mobile malware by hackers using masking tactics to hoodwink users and which could soon become the biggest cybersecurity problem yet.
To protect yourself, Njoroge advises that you should always download apps from official app stores and also practice caution when downloading any content from the internet. Always pay attention to anything suspicious in file name, size and extension.
Lastly is to use a reliable mobile security solution to protect you from the latest threats.
ESET combines with Google to improve the security of the Google Chrome browser
Google and ESET have combined Chrome’s sandbox technology with ESET’s detection engine to create the Chrome Cleanup tool included in the latest version of Google Chrome. The new version of tool has been developed with the vision of allowing internet users to browse the web safely and without interruption.
“Under the hood, we upgraded the technology we use in Chrome Cleanup to detect and remove unwanted software. We worked with IT security company ESET to combine their detection engine with Chrome’s sandbox technology. We can now detect and remove more unwanted software than ever before, meaning more people can benefit from Chrome Cleanup.” – Philippe Rivard, Product Manager, Chrome Cleanup.
Chrome Cleanup is now able to detect unwanted software such as pop-up ads, unwanted extensions, toolbars and browser redirecting software, and single it out for removal thereby allowing internet users to enjoy safer technology.
Chrome Cleanup runs in the background while users are browsing on Chrome and alerts users to potential threats. It then gives users the option to quickly remove this harmful or unwanted software and restore Chrome to its default settings.
“Using the internet should always be a smooth and safe experience for everyone,” said Juraj Malcho, Chief Technology Officer at ESET. ““For three decades, ESET has developed a number of security solutions that allow users to safely enjoy their technology and to mitigate a variety of cyber threats. Chrome Cleanup addresses unwanted software that can negatively influence a users’ experience on the internet.”
Cyber security attacks have become more frequent, more advanced and more difficult to identify. Take the worry out of your browsing experience and download the ESET protected Chrome Cleanup tool here.
Kenya has been widely celebrated as one of the foremost innovators around the question of financial inclusion. With the acclaim of being the leading nation in the adoption and use of mobile banking platforms such as M-PESA and Equitel, numerous fintech start-ups are opening office in the Silicon Savannah.
In Kenya, the effect of innovation by fintech companies has been brilliantly positive. Per a 2016 Finaccess Household Survey endorsed by the Central Bank of Kenya and the Kenya National Bureau of Statistics, the number of Kenyans formally included by the financial system has grown by 50% in the last ten years.
More than 75.3% of Kenyans are formally banked
Over three-quarters (75.3%) of Kenyans are now formally included, up from 66.8% in 2013. Financial exclusion, which is now down to 17.4%, has more than halved since 2006.
Cyber crime on the rise:
There is no simple way to say this. Kenyan bank accounts are at risk.
The latter statement has been evidenced by the statistics present in the recent Cyber security Report published by Serianu, which asserts that Kenya lost about $175million last year.
Moreover, the Report managed to establish that cyber criminals are deliberately targeting the Kenyan digital economy with the intention of wreaking havoc and making away with millions.
Essentially, in terms of cyber resilience, the Kenyan digital economy can be likened to a slow, plump gazelle stumbling through the “cyber-savannah” in the full view of agile, informed and hungry cyber-predators who have begun to sink their teeth into their sumptuous prize.
Cybersecurity is a budgetary concern
With more than 75.3% of Kenyan citizens formally included in financial services, one would logically expect a correspondent increase in cyber security investments in the financial services sector.
Notably, the Serianu 2016 Kenya Cyber security Report, which highlighted that about 44% of financial institutions run on a cyber security budget of $1-1,000 annually, whilst about 33% of financial institutions in Kenya have $0 spend on all matters cyber security.
44% of financial institutions run on a cyber security budget of $1-1,000 annually
Click to Tweet
Effective infrastructural cybersecurity measures come at a budgetary cost which must be respected by C-Suite executives. The threat landscape is constantly evolving as hackers collectively invest in their own expertise and tools to hack siloed
Financial organisations should staff more cyber security specialists
Notably, 63% of financial organisations in Kenya have an in-house cybersecurity department. However, only 29% of the employees within in-house cybersecurity departments in financial organisations are security certificate holders.
Financial organisations such as banks and fintech companies should ensure that their customers’ data is under the watch of certified cyber security professionals who can:
Promptly update their security infrastructure to match threat trends,
Clearly communicate the organisation’s cyber security needs to Board Executives,
Collaborate with digital product creators to ensure that their consumers enjoy safer technology,
Train other employees in online hygiene as a safety net against social engineering,
Swiftly respond to hacking incidences to mitigate losses and collect forensic data for litigation support.
Certified security specialists are a key asset for any financial organisation, as they not only guarantee their organisations’ business continuity by perpetuating trust and reliability of financial products, but also as business enablers who can assist in ensuring that there is security by design in the creation of new financial products.
Immature Data Protection Regulation:
There is no existing comprehensive data protection regulation in the jurisdiction of Kenya. This is in vast contrast to other thriving digital economies such as South Africa, states within the European Union and Canada.
One of the impactful consequences of poor data protection is the immensely secretive way through the occurrence of breaches is treated.
Financial institutions are not necessitated by any law to proactively inform the public regarding any substantial data breaches that have occurred to the detriment of their consumers.
This contrasts with the impending General Dara Protection Regulation in Europe, the Protection of Personal Information Act of South Africa and the Digital Privacy Act (whose adoption introduced mandatory notification via an amendment in the Personal Information Protection and Electronic Documents Act) who urge that any data breach that may result in a risk to the rights and freedoms of individuals should be reported to the relevant supervisory authority.
If unaddressed such breaches can have significant detrimental effect on individuals, i.e, discrimination, damage to reputation, financial loss, loss of confidentiality or any other significant economic or social disadvantage.
Under the Constitution of Kenya 2010, Kenyans’ consumer rights as well as the right to privacy has been asserted as a fundamental right that should be protected by the full legislative might of the Government.
Innovative legislators should get to work to protect the economy of the Republic of Kenya.
Large banks, microfinance institutions even cutting-edge fintech firms have been taking hooks to the jaw thrown by hungry cyber criminals who can see the vulnerabilities present within Kenya’s financial ecosystem.
The reputational harm to the financial sector has been immense as confidence in new, innovative financial products continues to decline sharply.
The finance market runs on the foundational principal of user trust. If financial institutions in Kenya do not champion the cyber security agenda, share threat intelligence to develop a fresh, synergised approach to cybercriminals, those heavy blows to their infrastructure will continue to wreak havoc to their stellar brands.