Monday, 13 April 2020 05:26

How the basic Nigerian email scam evolved into sophisticated malware attacks on corporates

Rate this item
(0 votes)

Yomi Kazeem

Nigerian internet fraudsters, best known for romance scams and infamous business propositions from “Nigerian princes,” are now operating with a lot more sophistication.

Last August, a major bust  by the Federal Bureau of Investigations (FBI) offered some insight into the growing scale and capabilities of Nigerian online fraudsters. Federal agents arrested 14 fraudsters operating within the US as part of a prolific network of scammers and named 66 others in a 252-count federal grand jury indictment. The fraudsters had defrauded victims of up to $10 million in one of the “largest cases of its kind in US history.” In total, the ring had attempted to steal $40 million from victims in 10 countries as well as the US.

A new report by Palo Alto Networks, a California-based cyber-security company which says it has researched Nigerian cyber-crime for five years, tries to show how these fraudsters have become a lot more proficient at scams over the past five years, employing more sophisticated tactics and tools to carry out Business Email Compromise (BEC) scams. It’s a long way from the classic “Yahoo Yahoo boys” scams 15 odd years ago.

While Nigerian actors were previously classed as “emerging” with regard to malware attacks, recent evidence suggests they “have evolved to a point where they are demonstrating signs of maturity consistent with established threat groups in their delivery techniques, malware packaging, and technical abilities,” Palo Alto Networks’ report notes. Last year, the firm’s malware tracking service identified around 27,000 samples of malware associated with Nigerian actors.

The researchers note the “dominant proportionality and sheer enormity” of BEC scam attempts from Nigerian actors. Last year, BEC scam attempts from these fraudsters resulted in an average of 92,739 attacks per month—172% increase from 2018.

Here’s how BEC scams work: fraudsters use hacked email accounts to convince businesses or individuals to make payments that are either bogus or similar to actual payments owed to legitimate companies. As part of the scam, fraudsters also learn about key personnel in companies who are responsible for those payments as well as the protocols necessary to perform wire transfers in various companies. They then target businesses and individuals that regularly perform such wire transfer payments.

Around $1.7 billion in losses were attributed to BEC attacks last year, more than losses to romance scams, phishing, identity theft, credit card fraud and ransomware, according to the annual report of the FBI’s Internet Crime Complaint Center.

The antics of these fraudsters have come at a wider cost for most Nigerians, as students, business people and tourists are often subject to extra scrutiny from international payment platforms, potential business partners and embassies for visa applications. While successive Nigerian governments have made significant efforts to curb international online fraud from the source at home by awarding notable powers to its anti-fraud agency, the state of the country’s weak economy and large swathes of educated, unemployed young college graduates means fraud is still seen by some as being worth the risk.

However, while growing sophisticated in their methods, Nigerian online fraudsters still “remain indiscriminate in their targeting” with attacks attempted on small and large businesses, healthcare companies as well US government institutions. However, high-tech companies bore the largest brunt of these efforts recording around 313,000 attacks last year—more than double the number in 2018.

And yet, the digital persona linked with young Nigerians has started to change markedly in recent years given several success stories in the country’s fledgling tech ecosystem over the last decade. Nigerian tech startups, innovating to solve many of the country’s systemic problems—from digital payments to online education—have attracted the most funding across Africa last year from major investors.

Nigerian software developers have also become widely sought after beyond the country’s shores, partly prompting a $100 million dollar bet on African development talent by software giant, Microsoft.

But even in Nigeria, local police have often “profiled” young men with laptops as online fraudsters as an excuse for harassment and extortion. This has led to significant protests and crowdfunding legal aid by the burgeoning tech community.

 

Quartz Africa

December 04, 2024

Entrepreneur turns Nigerian superfood into global export business

Interview with Timi Oke CO-FOUNDER and CEO, AGROEKNOR Timi Oke is the co-founder and CEO…
December 04, 2024

Namibia elects first female president

Netumbo Nandi-Ndaitwah of Namibia's ruling SWAPO party has been elected president and will be the…
December 04, 2024

‘Brain rot’ is Oxford English Dictionary’s word of 2024

Oxford University Press (OUP), the publisher of the Oxford English Dictionary, has announced Brain rot…
November 30, 2024

Family spends $4,500 on lavish funeral for ‘faithful’ SUV

An Indian family recently went viral for their decision to send their old Suzuki Wagon…
December 03, 2024

EFCC secures ‘single largest asset forfeiture’ of Abuja housing estate by court order from unnamed…

The Economic and Financial Crimes Commission (EFCC) has secured the final forfeiture of an estate…
December 04, 2024

What to know after Day 1014 of Russia-Ukraine war

RUSSIAN PERSPECTIVE Putin points to mass human rights violations, persecution of Church in Ukraine Mass…
November 29, 2024

Mixed reactions as Australia bans social media use for children under 16

Australians reacted on Friday with a mixture of anger and relief to a social media…
October 27, 2024

Nigeria awarded 3-0 win over Libya after airport fiasco

Nigeria have been awarded a 3-0 victory over Libya, and three vital points, from their…

NEWSSCROLL TEAM: 'Sina Kawonise: Publisher/Editor-in-Chief; Prof Wale Are Olaitan: Editorial Consultant; Femi Kawonise: Head, Production & Administration; Afolabi Ajibola: IT Manager;
Contact Us: [email protected] Tel/WhatsApp: +234 811 395 4049

Copyright © 2015 - 2024 NewsScroll. All rights reserved.