Nigeria's cyber incident response centre has confirmed six active malware families targeting Android devices nationwide. Here's what each one does and how to check if you're at risk.
Nigeria's Computer Emergency Response Team (ngCERT) the country's national cyber incident response centre has issued a direct advisory confirming six malware families actively compromising Android devices across the country right now. With Nigeria recording over 182.2 million phone subscriptions as of January 2026, this isn't a niche technical warning. It's relevant to nearly every Android user in the country.
Here's exactly what ngCERT found, what each malware family actually does, and what to do about it.
The Six Malware Families ngCERT Identified
According to the official advisory, the following malware families are actively compromising Android devices in Nigeria:
| Malware | Also Known As | What It Does |
|---|---|---|
| Android Backdoor | — | Opens a hidden access point, letting attackers operate on your device without your knowledge |
| Prizmes | Linked to BADBOX | Embeds in system partitions, resistant to removal even after a factory reset |
| Hummer | HummingBad | Roots the device for privilege escalation and ad-fraud revenue generation |
| Rootnik | — | Exploits older Android vulnerabilities to gain root access |
| Triada | — | Embeds deep in system partitions; among the hardest variants to fully remove |
| Uupay | — | Pushes unwanted ads and harvests device data |
These variants spread through pre-installed malicious firmware (meaning some devices arrive compromised out of the box), repackaged mobile apps disguised as legitimate software, and downloads from untrusted third-party app stores rather than the official Google Play Store.
What Happens Once a Device Is Infected
According to ngCERT's advisory, once these malware families gain root access, they inject code into core Android system processes (like Zygote) to establish long-term persistence. From there, the documented impacts include:
- Data theft access to IMEI numbers, device IDs, contacts, SMS messages, and stored credentials
- Credential interception capturing login details, including for banking apps
- Financial fraud via ad-click manipulation and unauthorized transactions
- Botnet integration your device silently becomes part of a larger network used for coordinated attacks elsewhere
- Device instability from unwanted apps, excessive ads, and abnormal network traffic
- Additional malware deployment an infected device can be used as a gateway to install further malicious software
ngCERT describes the combined impact as severe, warning of consequences ranging from sensitive data loss to large-scale botnet participation and a broader erosion of trust in mobile ecosystems.
A critical detail: Triada and Prizmes/BADBOX specifically embed themselves within system partitions meaning a standard factory reset will not remove them. This is a meaningful departure from how most people think about "cleaning" an infected phone.
This Is Part of a Wider Pattern in 2026
This six-family advisory isn't ngCERT's only Android warning this year. The agency has separately issued alerts on:
- Android.BadBox2: a supply-chain attack where low-cost Android devices, tablets, connected TVs, and digital photo frames arrive pre-infected at the firmware level before ever reaching a buyer.
- Tria Stealer: spread specifically through fake wedding and event invitations sent via WhatsApp and Telegram, tricking users into downloading a malicious APK that hijacks WhatsApp and Telegram accounts and intercepts OTPs.
- A zero-click Android vulnerability (patched in the May 2026 Android security update) that allowed remote device compromise with no user interaction required at all.
- Pixnapping, a newly disclosed attack capable of covertly reading on-screen data, including two-factor authentication codes within seconds, affecting Android versions 13 through 16.
The throughline across all of these: Nigeria's enormous, fast-growing Android user base has become a consistent, high-value target throughout 2026.
How to Protect Your Device
1. Buy smart. Purchase phones and Android devices only from trusted, authorized retailers. Be cautious of unusually cheap devices supply-chain infections like BadBox 2.0 specifically target low-cost, uncertified hardware.
2. Keep your device updated. Install the latest Android security patches as soon as they're available, and enable automatic updates where possible.
3. Only install apps from the Google Play Store. Repackaged and third-party-sourced apps are one of the primary infection vectors ngCERT identified.
4. Be suspicious of unexpected APK files even ones that appear to come from friends or family, such as "wedding invitations" or event links sent via WhatsApp or Telegram.
5. Watch for the warning signs: unusual battery drain, unexplained data usage spikes, apps you don't remember installing, or settings changing on their own.
6. If you suspect infection, don't assume a factory reset will fix it. For the system-partition-embedded variants (Triada, Prizmes/BADBOX), a standard reset may not remove the malware. Contact a certified technician, or report the issue to ngCERT through its official channels.
Frequently Asked Questions
What are the six malware families ngCERT identified? Android Backdoor, Prizmes (linked to BADBOX), Hummer (also known as HummingBad), Rootnik, Triada, and Uupay.
Will a factory reset remove this malware? Not necessarily. Triada and Prizmes/BADBOX embed themselves within system partitions and can survive a standard factory reset specialized remediation may be required.
How do I know if my Android phone is infected? Watch for unusual battery drain, unexpected data usage, unfamiliar apps, or device settings changing without your input. If you suspect an infection, contact a certified technician rather than relying solely on a factory reset.
How does this malware typically spread in Nigeria? Primarily through pre-installed firmware on low-cost devices, repackaged apps disguised as legitimate software, and downloads from unofficial third-party app stores as well as malicious APK files sent through messaging apps.
Who should I report a suspected infection to? ngCERT accepts reports through its official channels at cert.gov.ng, which also publishes ongoing security advisories for individuals and organizations.
Source: Nigeria Computer Emergency Response Team — ngCERT cert.gov.ng
Related reading: NIGERIA NAMED AFRICA'S MOST SPAMMED COUNTRY AS FRAUD CALLS HIT 51%
NITDA RAISES ALARM OVER AI-POWERED "DEEPLOAD" MALWARE TARGETING NIGERIA
More on Cyber Watch
