DeepLoad Malware Targets Nigerian Entities
Analysis based on 8 articles · First reported May 07, 2026 · Last updated May 07, 2026
The DeepLoad malware poses a significant threat to Nigeria's financial markets by targeting financial institutions and potentially leading to unauthorized access to bank accounts, mobile money services, and payment cards. This could result in identity fraud, financial fraud, and operational disruptions for affected organizations, impacting investor confidence and market stability.
The Nigeria — National Information Technology Development Agency has issued a critical cybersecurity alert regarding a new AI-powered malware named DeepLoad, which is actively targeting Nigerian government agencies, financial institutions, businesses, and individuals. DeepLoad is designed to infiltrate systems, steal sensitive information, and evade conventional antivirus detection. It spreads through deceptive website prompts that trick users into executing malicious commands, silently installing itself and harvesting credentials from major web browsers. A particularly dangerous feature is its hidden WMI-based persistence mechanism, allowing it to reactivate days after apparent removal. The malware can lead to unauthorized access to bank accounts, identity fraud, operational disruptions for organizations, and compromise classified government networks, posing national security risks. The Nigeria — National Information Technology Development Agency has advised immediate protective measures, including avoiding pasting commands from websites, scanning USB drives, enabling two-factor authentication, and blocking malicious domains. This warning comes amidst a rising wave of cyberattacks in Nigeria, with institutions like Nigeria — Corporate Affairs Commission, Nigeria — Economic and Financial Crimes Commission, Remita Payment Services, and Sterling Bank having recently faced cyber incidents.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard