Advisory ID: NCC-CSIRT-2026-037
Summary:
The NCC-CSIRT wishes to alert the Nigerian Telecommunications Service Providers to reports of Russian-linked disinformation and influence campaigns targeting Africa's information space. According to an alert conveyed by the Office of the Secretary to the Government of the Federation (OSGF), an assessment by Collaboration on International ICT Policy for East and Southern Africa (CIPESA) identified at least 80 such campaigns in 2024 affecting over 22 African countries, including Nigeria. The campaigns reportedly use local influencers and digital content creators to spread foreign-backed narratives while concealing their origins. Telecom Service Providers are advised to strengthen monitoring, report suspicious activities promptly, and remain vigilant against information manipulation and related cyber threats.
Damage: High
Probability: High
Product (s): Not Applicable (N/A)
Version (s): Not Applicable (N/A)
Platform (s): Telecommunications Networks and Internet-Facing Information Systems
Description:
The NCC-CSIRT wishes to draw the attention of Nigerian Telecommunications Service Providers to reports of Russian-linked disinformation campaigns targeting Africa's information space.
According to a 1 July 2026 CIPESA assessment, at least 80 Russian-linked disinformation campaigns targeted over 22 African countries in 2024. Nigeria was identified among the affected countries, alongside Kenya, Ethiopia, and Ghana.
The campaigns reportedly leverage local influencers, bloggers, journalists, activists, content creators, online platforms, and other actors to disseminate narratives while concealing foreign sponsorship. They may also utilize social media accounts, Telegram channels, web portals, and other digital infrastructure, including AI-generated and manipulated content.
Given the approaching electoral cycle and the growing reliance on digital platforms for information dissemination, heightened vigilance is advised. While no specific technical Indicators of Compromise (IoCs) have been provided, Telecom Service Providers should focus on monitoring, evidence preservation, and timely reporting of suspicious activities.
Consequences:
Potential consequences associated with foreign information manipulation and disinformation campaigns may include:
- Potential impact on Critical National Information Infrastructure (CNII), telecommunications services, and associated online platforms or resources.
- Reputational and operational impact on service providers.
- Manipulation of public perception and loss of trust in institutions.
- Increased exposure to phishing, fraud, impersonation, and other cyber threats.
- Spread of false or AI-generated information, potentially causing social tension and disruption.
Threat Types:
- Potential Election-Related Information Manipulation
- Coordinated Cyber-Enabled Influence Activity
- Foreign Information Manipulation and Influence (FIMI)
- Disinformation Campaigns
- Coordinated Inauthentic Behaviour
- Social Engineering and Influence Operations
- AI-Generated and Manipulated Content
- Malicious Online Infrastructure
- Abuse of Telecommunications Resources
Solutions/Mitigations:
NCC-CSIRT encourages telecommunications service providers to:
- Enhance monitoring of networks, Internet-facing systems, and security telemetry to detect suspicious activities.
- Maintain accurate asset inventories of critical network infrastructure and Internet-facing resources.
- Strengthen detection capabilities for phishing, impersonation, social engineering, deceptive content, and suspicious online infrastructure.
- Preserve logs and evidence related to suspicious activities in line with legal and regulatory requirements.
- Leverage threat intelligence from NCC-CSIRT and other trusted authorities to support analysis and response.
- Improve coordination and information sharing among SOC, NCC-CSIRT, fraud management, and network operations teams for timely threat detection and response.
References:
Office of the Secretary to the Government of the Federation (OSGF): “Pan African Non-Governmental Organization Warns of Russian-Linked Disinformation Campaigns on Africa’s Information Space.”
Advisory ID: NCC-CSIRT-2026-036
Summary:
The NCC-CSIRT wishes to inform Nigerian Telecommunications Service Providers of emerging security concerns related to the BitChat decentralized messaging application. Of particular concern is BitChat's decentralized Bluetooth mesh architecture, which enables communication without internet connectivity, mobile networks, centralized servers, user registration, or phone numbers. These characteristics may limit the effectiveness of conventional monitoring and oversight mechanisms and could potentially be exploited by malicious actors to facilitate covert communications.
Damage: Critical
Probability: High
Product: BitChat Messaging Application
Version: All supported versions
Platform:
- Android
- iOS
- Windows
- macOS
- Linux
Description:
According to a cyber threat intelligence report, authorities have raised concerns regarding the potential security implications of the BitChat decentralized messaging application. Unlike conventional messaging platforms, BitChat operates using Bluetooth mesh networking technology, enabling nearby devices to exchange messages without relying on internet connectivity, cellular networks, centralized servers, user accounts, or telephone numbers.
This decentralized architecture allows communications to continue during internet outages or network disruptions. While such technologies offer legitimate benefits in terms of privacy, resilience, and communications continuity, they may also pose challenges for law enforcement and national security agencies if exploited by malicious actors to facilitate anonymous or infrastructure-independent communications that evade traditional monitoring and investigative processes.
Telecommunications Service Providers are therefore encouraged to remain vigilant, monitor developments relating to decentralized communication technologies, and maintain close collaboration with the NCC-CSIRT and other relevant government stakeholders on any emerging cybersecurity risks or concerns.
Consequences:
Potential exploitation of BitChat may result in:
- Reduced communications visibility by conventional monitoring mechanisms.
- Increased difficulty in conducting lawful investigations involving decentralized communications.
- Potential coordination of criminal or malicious activities through peer-to-peer communications.
- Challenges to digital forensic investigations where communications occur outside traditional telecommunications infrastructure.
- Increased operational challenges during emergency situations or civil disturbances.
Threat Types:
- Anonymous Communications
- Decentralized Messaging
- Covert Communications
- Privacy-Enhancing Technology
- Potential Criminal Abuse
Solutions/Mitigations:
NCC-CSIRT strongly recommends the following:
- Continue monitoring developments involving decentralized and peer-to-peer communication technologies.
- Maintain close collaboration with NCC-CSIRT and relevant government agencies regarding emerging cyber threats.
- Review incident response procedures relating to investigations involving decentralized communication platforms.
- Enhance threat intelligence collection and analysis on emerging privacy-enhancing technologies that could be abused by threat actors.
- Continue implementing robust network security monitoring, logging, and anomaly detection capabilities across telecommunications infrastructure.
References:
- Office of the National Security Adviser (ONSA): Notification regarding national security concerns associated with the BitChat decentralized messaging application.
- https://edunovations.com/currentaffairs/national/bitchat-app-security-concerns/
- https://economictimes.indiatimes.com/news/india/govt-orders-github-to-remove-bluetooth-based-chat-app-bitchat-over-security-concerns-jack-dorsey/articleshow/132602726.cms#google_vignette
Advisory ID: NCC-CSIRT-2026-032
Summary:
The Nigerian Communications Commission Computer Security Incident Response Team (NCC-CSIRT) has identified a phishing campaign leveraging a fraudulent promotional webpage hosted on https://ibaidad.com/pella-jarvis-wedding. The campaign falsely promises 10GB of free mobile data and ₦5,000 airtime in exchange for users providing their mobile phone numbers and sharing the malicious link through WhatsApp. The campaign employs social engineering techniques to harvest user information and rapidly propagate itself through messaging platforms. Telecommunications Service Providers are advised to implement appropriate security measures to protect subscribers and mitigate the spread of the malicious campaign.
Damage: High
Probability: High
Description:
NCC-CSIRT has observed a phishing campaign hosted on the domain ibaidad.com, specifically the webpage:
https://ibaidad.com/pella-jarvis-wedding
The webpage falsely advertises a promotional offer claiming that users can receive 10GB of free mobile data and ₦5,000 airtime in celebration of an alleged wedding event.
Visitors are instructed to enter their mobile phone numbers before being directed to share the webpage with multiple WhatsApp contacts or groups to qualify for the purported reward. Such behaviour is consistent with social engineering campaigns designed to harvest user information while increasing the campaign's distribution through trusted contacts.
Independent threat intelligence sources have classified the domain as suspicious and associated with phishing activities. Although there is currently no evidence that the campaign exploits software vulnerabilities in mobile operating systems or telecommunications infrastructure, it poses a significant risk to subscribers through deception and manipulation.
Given the widespread use of mobile messaging platforms in Nigeria, Telecommunications Service Providers are encouraged to strengthen monitoring, web filtering, subscriber awareness, and threat intelligence activities to minimise the impact of this campaign.
Consequences:
Successful influence operations may result in:
- Collection of subscribers' mobile phone numbers and other personal information.
- Increased exposure of subscribers to phishing, fraud, and identity theft.
- Rapid propagation of malicious links through WhatsApp and other messaging platforms.
- Financial losses arising from subsequent scam campaigns.
- Reduced customer trust in legitimate promotional campaigns.
- Increased security and customer support incidents for Telecommunications Service Providers.
Threat Types:
- Phishing
- Social Engineering
- Fraudulent Promotional Campaign
- Credential and Personal Information Harvesting
- Mobile Messaging Abuse
- Malicious URL Distribution
Solutions/Mitigations:
NCC-CSIRT strongly recommends the following:
- Block the identified URL and associated domain through DNS filtering, secure web gateways, and other available network security controls.
- Monitor network traffic for access to the identified indicators and similar phishing infrastructure.
- Disseminate this advisory to relevant cybersecurity, fraud management, and network operations personnel.
- Notify subscribers through official communication channels about the ongoing phishing campaign.
- Advise subscribers not to provide personal information in response to unsolicited promotional offers or requests received via websites or messaging applications.
- Encourage subscribers to verify promotional offers only through official Telecommunications Service Provider channels.
References:
https://ibaidad.com/pella-jarvis-wedding
https://gridinsoft.com/online-virus-scanner/url/ibaidad-com
https://any.run/report/e48bd9676bfdb8c1121e7d4203171c8c21917f66057d806c1a323fe4534ce454/d78c7e83-3707-4959-a2b9-464e556dade4
Awareness Advisory on Reported China-Linked Cyber Espionage Campaign Targeting Research Institutions
Advisory ID: NCC-CSIRT-2026-031
Summary:
The NCC-CSIRT has alerted Telecommunications Service Providers to a cyber espionage campaign reportedly linked to a China-associated threat actor, UNC6508, based on information from the OSGF and Google’s Threat Intelligence Group (GTIG). The campaign targeted research institutions by exploiting vulnerabilities in REDCap servers, deploying custom malware, and stealing sensitive data. Although Nigerian telecommunications infrastructure is not currently a direct target, Telecommunications Service Providers are encouraged to stay vigilant and strengthen cybersecurity measures to support the resilience of Nigeria’s digital ecosystem.
Damage: Critical
Probability: Medium
Product(s):
- REDCap (Research Electronic Data Capture) Platforms
- Research Information Management Systems
- Institutional Email Systems
- Clinical Research Databases
- Academic and Healthcare Information Systems
Platform(s):
- Windows
- Linux
- Web-Based REDCap Deployments
- Enterprise Email Platforms
- Research Network Infrastructure
Description:
According to information received from the Office of the Secretary to the Government of the Federation (OSGF), citing findings reportedly published by Google's Threat Intelligence Group (GTIG), a China-linked threat actor identified as UNC6508 has conducted cyber-espionage operations targeting research organisations in North America.
The campaign reportedly exploited vulnerabilities in REDCap servers to gain unauthorised access to institutional networks. Following compromise, the attackers allegedly deployed a custom malware known as INFINITERED, designed to maintain persistence by surviving software updates and enabling long-term access to compromised systems. The report also indicates that the threat actor manipulated email forwarding mechanisms to collect sensitive communications and exfiltrate valuable research data covertly.
Although the reported campaign does not directly target telecommunications infrastructure, Telecommunications Service Providers support the digital connectivity upon which many critical sectors, including healthcare, higher education, research institutions, and government agencies, depend. Accordingly, Telecommunications Service Providers are encouraged to remain aware of emerging cyber espionage campaigns and continue strengthening cybersecurity monitoring, information sharing, and support for institutional customers that may be affected by similar threats.
Consequences:
Successful exploitation may result in:
- Unauthorized access to sensitive information.
- Theft of intellectual property and research data.
- Persistent compromise of enterprise networks.
- Unauthorized monitoring of institutional email communications.
- Exposure of confidential research and healthcare information.
- Reputational, operational, and regulatory impacts.
Threat Types:
- Advanced Persistent Threat (APT)
- Cyber Espionage
- Unauthorized Access
- Malware Deployment
- Data Exfiltration
- Credential Compromise
- Email Surveillance
- Intelligence Collection
Solutions/Mitigations:
Successful influence operations may result in:
- Disseminate this advisory to relevant cybersecurity and network operations personnel for situational awareness.
- Continue monitoring global cyber threat intelligence concerning Advanced Persistent Threat (APT) activities.
- Encourage enterprise customers, particularly research, healthcare, and academic institutions, to implement timely security updates and vulnerability management practices.
- Support the adoption of Multi-Factor Authentication (MFA), robust access controls, and continuous security monitoring across enterprise environments.
- Maintain close collaboration with NCC-CSIRT and relevant national authorities regarding significant cybersecurity incidents affecting critical sectors.
- Promote cybersecurity awareness among institutional customers regarding evolving cyber espionage threats.
References:
Office of the Secretary to the Government of the Federation (OSGF), Nigeria. GOOGLE THREAT GROUP REPORT ALLEGES ESPIONAGE BY CHINA-LINKED HACKERS. Confidential Correspondence dated 14 July 2026.
Advisory ID: ngCERT-2026-060010
Damage: Critical
Probability: High
Platform(s): Email Systems
SUMMARY
ngCERT alerts organisations to a sophisticated multi-stage phishing campaign that leverages legitimate email services and fraudulent Code of Conduct notifications to facilitate Adversary-in-the-Middle (AiTM) attacks. The campaign uses carefully crafted phishing emails to lure users to attacker-controlled proxy servers that replicate legitimate authentication pages in real time. This enables threat actors to intercept user credentials, Multi-Factor Authentication (MFA) responses, authentication cookies, and session tokens, while gaining unauthorized access to user accounts. Organisations are advised to strengthen email security, authentication controls, and user awareness to mitigate this evolving threat.
DESCRIPTION
The campaign begins with carefully crafted phishing emails disguised as legitimate corporate communications, including Code of Conduct or compliance updates, which use urgency-driven messaging to prompt immediate user action. Victims are redirected through multiple stages to highly convincing authentication pages operating as reverse proxy servers. These servers relay authentication requests while capturing usernames, passwords, Multi-Factor Authentication (MFA) responses, authentication cookies, and authenticated session tokens in real time. The use of enterprise-grade phishing templates, multi-step redirection, CAPTCHA barriers, and other evasion techniques designed to bypass both technical security controls and user awareness highlights its level of sophistication. This further demonstrates a strategic effort to maximise unauthorized access, facilitate lateral movement, compromise sensitive information, and enable Business Email Compromise (BEC) and data exfiltration. The campaign primarily targets privileged users and organisations within finance, healthcare, and technology sectors.
CONSEQUENCES
Successful exploitation of this campaign could result in:
- Unauthorized access to user accounts through the theft of credentials, authentication cookies, and MFA session tokens.
- Business Email Compromise (BEC) and financial fraud using compromised trusted accounts.
- Exposure of sensitive government and organisational information.
- Lateral movement within enterprise environments and compromise of additional systems and resources.
- Operational disruption, reputational damage, and regulatory or compliance consequences.
SOLUTION/MITIGATION
ngCERT recommends that organisations implement the following security measures:
- Deploy phishing-resistant authentication methods such as FIDO2 Security Keys or Passkeys, and enforce Multi-Factor Authentication (MFA) with risk-based access controls.
- Implement advanced email security solutions to detect and block phishing emails, malicious links, and spoofed messages.
- Continuously monitor authentication logs for suspicious sign-in activities and promptly revoke compromised sessions, reset credentials, and invalidate authentication tokens.
- Disable legacy authentication protocols, promptly apply security updates, and implement recommended security configurations.
- Conduct regular phishing awareness training and educate users to verify login URLs and report suspicious emails.
- Deploy Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), and identity threat detection solutions to identify credential theft, session hijacking, and anomalous authentication activities.
- Regularly review and test incident response plans for phishing, credential compromise, and Business Email Compromise (BEC) incidents.
HYPERLINK
- https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/?msockid=095d8322290c6f3e3bf69509281e6e21
- https://thehackersnews.com/2026/05/microsoft-details-phishing-campaign.html
- https://msftnewsnow.com/microsoft-code-of-conduct-phishing-aitm-token-thef/
- AI-Driven Social Engineering and Deepfake Threats: Lessons from Bayer's Psychology-Based Cybersecurity Awareness Program
- Chinese-Linked Hackers Using Covert Networks of Compromised Devices to Mask Malicious Activities
- DDoS Threats Driven by Malware Strains Targeting the Communications Sector
- Security Advisory on Critical Dangers of Expired and Mismanaged Digital Certificates – Urgent Management Required