Close Menu
Innovation Village | Technology, Product Reviews, Business
    Facebook X (Twitter) Instagram
    Saturday, June 7
    • About us
      • Authors
    • Contact us
    • Privacy policy
    • Terms of use
    • Advertise
    • Newsletter
    • Post a Job
    • Partners
    Facebook X (Twitter) LinkedIn YouTube WhatsApp
    Innovation Village | Technology, Product Reviews, Business
    • Home
    • Innovation
      • Products
      • Technology
      • Internet of Things
    • Business
      • Agritech
      • Fintech
      • Healthtech
      • Investments
        • Cryptocurrency
      • People
      • Startups
      • Women In Tech
    • Media
      • Entertainment
      • Gaming
    • Reviews
      • Gadgets
      • Apps
      • How To
    • Giveaways
    • Jobs
    Innovation Village | Technology, Product Reviews, Business
    You are at:Home»Cybersecurity»NCC warns that TikTok’s “Invisible Challenge” exposes devices to an Information-Stealing Malware

    NCC warns that TikTok’s “Invisible Challenge” exposes devices to an Information-Stealing Malware

    1
    By Smart Megwai on December 6, 2022 Cybersecurity, Hacks, Social Media, TikTok, Video on Demand

    The Nigerian Communication Commission, through its Computer Security Incident Response Team (NCC-CSIRT), have raised an alarm on the threat posed by a TikTok viral challenge called “Invisible Challenge”.

    The Commission’s Director of Public Affairs, Mr Reuben Muoka, said that hackers are using the challenge to spread an information-stealing malware known as WASP stealer.

    WASP, similar to the Vidar Stealer, is the name of an information-stealing malware that steals victims’ passwords, credit card details, cryptocurrency wallets, and personal files and sends them to the threat actor.

    Information stolen using WASP malware can be misused to make fraudulent purchases and transactions, steal identities, and more. Depending on the type of hijacked accounts, they can be misused to send spam, deliver malware, access sensitive information, etc.

    The NCC-CSIRT explained that TikTok’s Invisible Challenge involves the user recording a video while naked using TikTok’s Invisible Body filter, which in turn replaces the body with a blurry background.

    Threat actors exploit the “Invisible Challenge” by offering a fake (trojanized) application that supposedly exposes nude bodies. Users infect their devices with WASP after downloading and installing a fake app.

    This fake app is promoted via TikTok videos with a link to download the software, known as “unfilter”. Anyone who, therefore, clicks on the link and tries to download the software is infected with the WASP stealer.

    According to NCC, “Suspended accounts had amassed over a million views after initially posting the videos with a link. Following the link leads to the “Space Unfilter” Discord server, which had 32,000 members at its peak but has since been removed by its creators.”

    “Successful installation will allow the malware to harvest keystrokes, screenshots, network activity, and other information from devices where it is installed. It may also covertly monitor user behaviour and harvest Personally Identifiable Information (PII), including names and passwords, keystrokes from emails, chat programs, websites visited, and financial activity. This malware may be capable of covertly collecting screenshots, video recordings, or the ability to activate any connected camera or microphone,” the NCC-CSIRT team explained.

    The Team recommended practising good password hygiene by adopting measures like using a password manager and avoid clicking on suspicious links, as well as installing anti-malware software on all of your devices.

    How to avoid installation of malware

    1. Always download softwares from reliable sources, that is, official websites and stores.
    2. Avoid using P2P networks, shady pages, third-party downloaders, free file hosting pages, and similar sources to download apps or files.
    3. Keep the operating system and installed programs updated.
    4. Never use third-party tools to update or activate any software.
    5. Do not trust advertisements and links on suspicious web pages.
    6. Examine emails containing links or attachments before clicking/opening them.

    Related

    Android target for mobile malware Cybersecurity Awareness data security Nigerian Communications Commission (NCC) TikTok Safety Trojans
    Share. Facebook Twitter Pinterest LinkedIn Email
    Smart Megwai
    • Facebook
    • X (Twitter)
    • Instagram
    • LinkedIn

    Smart is a Tech Writer. His passion for educating people is what drives him to provide practical tech solutions which helps solve everyday tech-related issues.

    Related Posts

    TikTok launches TikTok for Artists to empower Artists’ Growth and fan engagement

    Elon Musk Launches XChat: Can It Compete with WhatsApp and Telegram?

    What to Do When Your Spotify Account Gets Hacked

    1 Comment

    1. Pingback: NCC warns Android device owners of yet another dangerous malware, Schoolyard Bully Trojan - Innovation Village | Technology, Product Reviews, Business

    Leave A Reply Cancel Reply

    You must be logged in to post a comment.

    Copyright ©, 2013-2024 Innovation-Village.com. All Rights Reserved

    Type above and press Enter to search. Press Esc to cancel.