NITDA Issues Fresh Cybersecurity Alert Over AI-Powered DeepLoad Malware

3 minutes read

The National Information Technology Development Agency (NITDA) has issued a fresh cybersecurity warning over a new artificial intelligence-powered malware known as DeepLoad, cautioning that the threat is actively targeting Nigerian government agencies, financial institutions, businesses, and individual users.

The warning was contained in a critical advisory released by NITDA’s Computer Emergency Readiness and Response Team (CERRT.NG) on May 6 and shared through the agency’s official X platform.

According to the agency, DeepLoad is an advanced AI-enhanced malware designed to infiltrate computer systems, steal sensitive information, and evade traditional antivirus detection mechanisms.

NITDA explained that the malware spreads through deceptive social engineering tactics involving fake website error prompts that trick unsuspecting users into copying and executing malicious commands on their computers.

“The malware is distributed through a social engineering technique involving fake website errors,” the agency stated.

Once activated, the malware reportedly installs itself silently on infected systems and begins harvesting stored passwords, credentials, and sensitive data from major web browsers.

NITDA further warned that DeepLoad uses artificial intelligence to avoid detection by security software, making it significantly more dangerous than conventional malware.

One of the most alarming features identified by the agency is the malware’s ability to survive attempted removal through a hidden Windows Management Instrumentation (WMI)-based persistence mechanism.

According to NITDA, the infection can reactivate itself up to three days after users believe it has been successfully removed.

The agency described the threat as severe and urged both organisations and individuals to implement immediate protective measures.

NITDA warned that successful infections could give cybercriminals access to victims’ bank accounts, payment cards, mobile money platforms, passwords, and personal documents, potentially leading to identity theft and financial fraud.

For businesses and government institutions, the agency said attacks could trigger operational disruptions, compromise classified systems, and expose critical national infrastructure to cyber risks.

To reduce exposure, NITDA advised Nigerians never to paste commands from websites into their computers, stressing that legitimate software providers do not require such actions.

The agency also cautioned against opening suspicious installation files from USB drives and urged users to scan all external devices with updated antivirus software before use.

Additional recommendations included enabling two-factor authentication on important accounts, avoiding the storage of banking passwords on browsers, and reviewing browser extensions for unauthorised installations.

For organisations, NITDA recommended immediate staff sensitisation, enabling PowerShell Script Block Logging across Windows systems, and blocking malicious domains linked to the malware at firewall and DNS levels.

The agency also urged institutions to inspect systems for hidden WMI Event Subscriptions that may allow the malware to survive standard cleanup procedures.

NITDA advised organisations that suspect infections to immediately disconnect affected systems from the internet, isolate compromised devices, change passwords using clean systems, activate incident response teams, and report incidents within 72 hours as required by law.

The latest warning comes amid rising concerns over cyberattacks targeting Nigeria’s digital infrastructure and financial systems.

In recent months, agencies including the Nigeria Data Protection Commission (NDPC) have raised alarms over coordinated cyber threats affecting banks, payment platforms, and government institutions.

The warning also follows reports of a suspected cyberattack on the Corporate Affairs Commission (CAC), which temporarily shut down its website after millions of documents were reportedly exposed during a security breach.

Share this article

Share your Comment

guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Read More

Trending Posts

Quick Links