NITDA warns of AI malware targeting Nigerian institutions

The National Information Technology Development Agency has issued a security alert over a new artificial intelligence-powered malware known as DeepLoad, warning that it is actively targeting government agencies, financial institutions, businesses, and individuals across Nigeria.
nThe warning was released on its X handle on Wednesday through the agency’s Computer Emergency Readiness and Response Team as cyberattacks against Nigerian organisations continue to rise.
nAccording to the agency, DeepLoad is a highly advanced malware strain designed to steal sensitive information while avoiding detection by traditional antivirus systems. It spreads through social engineering tactics, particularly fake website error prompts that trick users into running malicious commands.
n“The malware is distributed through a social engineering technique involving a fake website error,” NITDA stated in its advisory.
nOnce executed, the malware installs itself quietly on a device and begins extracting stored credentials and sensitive data from major web browsers. It then uses artificial intelligence techniques to help it evade detection and remain active.
n“Once executed, DeepLoad silently installs itself, harvests stored credentials and sensitive data from major browsers, and leverages artificial intelligence to evade antivirus detection,” the agency said.
nNITDA also warned that DeepLoad has a persistence mechanism that makes it especially difficult to remove. The malware can reactivate itself days after it appears to have been deleted.
n“Critically, the malware incorporates a hidden WMI-based persistence mechanism capable of reactivating the infection up to three days after apparent removal,” the advisory stated.
nThe agency described the threat as serious and already active, urging immediate protective measures. “Given its severity and confirmed active targeting of Nigerian entities, all organizations and individuals must implement the protective measures outlined in this advisory immediately,” it added.
nNITDA warned that individuals, businesses, and government institutions are all at risk. A successful infection could give attackers access to bank accounts, mobile money services, payment cards, passwords, and sensitive personal documents.
nThe agency also raised concerns about identity theft, saying stolen information could be used to impersonate victims for financial gain.
nFor organisations, NITDA said infections could lead to major operational disruptions, including system shutdowns and recovery processes. It also warned that breaches in government systems could compromise classified data and national security infrastructure.
nTo prevent infection, NITDA advised users not to copy or execute commands from unknown websites, stressing that legitimate software providers do not require such actions.
nIt also warned against installing software from unverified USB drives and recommended scanning all external storage devices before use.
nOther key recommendations included “Enabling two-factor authentication on important accounts, avoiding storing banking passwords in browsers, reviewing browser extensions for suspicious activity, blocking known malicious domains at the firewall and DNS level, and enabling advanced logging tools on Windows systems
nOrganisations were also urged to educate staff, monitor systems for hidden persistence mechanisms, and immediately isolate any suspected infected devices.
nNITDA concluded that any confirmed or suspected incident should be reported quickly, with affected systems disconnected from the internet, passwords reset from secure devices, and internal response teams activated within hours to contain the threat.
n nRelated Stories
Breaking NewsJAMB NO LONGER MANDATORY FOR ADMISSION – FG EMPOWERS INSTITUTIONS TO ADMIT STUDENTS USING SSCE RESULTS
The Federal Government, through the Ministry of Education, has announced a new policy granting Nigerian tertiary institutions greater autonomy in thei
Breaking NewsHow We Kidnapped Bayelsa Judge - Suspects
Suspects in the abduction of Justice Ebiyerin Omukoro have narrated how they committed the crime. rnrnEight of the suspects, which included six males
Breaking NewsDr. Dennis Otuaro Volunteer Media Team Berates SaharaReporters Over Unfounded Allegations Against PAP Administrator
The attention of the Dr. Dennis Otuaro Volunteer Media Team has been drawn to a recent misleading and malicious publication by SaharaReporters, accusi
