NITDA Issues Fresh Cybersecurity Alert Over AI-Powered ‘DeepLoad’ Malware Attacks

May 7, 2026

The National Information Technology Development Agency (NITDA) has raised a fresh cybersecurity alarm over a new artificial intelligence-powered malware identified as “DeepLoad,” warning that the threat is actively targeting Nigerian government agencies, financial institutions, businesses and individuals.

In a critical advisory issued through the Computer Emergency Readiness and Response Team (CERRT.NG), the agency said the malware employs sophisticated social engineering techniques to infiltrate systems, steal sensitive data and evade conventional antivirus detection.

The advisory, titled “Critical Advisory: DeepLoad AI-Powered Malware Actively Targeting Nigerian Organizations,” described the malware as a major cyber threat with the potential to compromise public institutions, critical infrastructure and personal financial information.

Join our WhatsApp Channel

READ ALSO :

UK Pledges Stronger Cybersecurity Partnership with Nigeria Amid Rising Cyber Threats

According to NITDA, DeepLoad is primarily distributed through fake website error messages that deceive victims into copying and pasting malicious commands into their computers.

“Once executed, DeepLoad silently installs itself, harvests stored credentials and sensitive data from major browsers, and leverages artificial intelligence to evade antivirus detection,” the agency stated.

NITDA further disclosed that the malware contains a hidden Windows Management Instrumentation (WMI)-based persistence mechanism that can reactivate the infection up to three days after apparent removal.

The agency warned that successful infections could lead to unauthorized access to bank accounts, mobile money platforms and payment cards, as well as the theft of passwords, confidential documents and personal information stored in web browsers.

It added that the malware could also facilitate identity fraud, disrupt organisational operations and potentially compromise classified government networks, posing what it described as a direct threat to national security.

READ MORE :

NITDA, CAC Activate Cybersecurity Measures Over System Concerns

The advisory identified government agencies, public institutions, banks, critical infrastructure operators, businesses of all sizes and individuals using online banking or email services as the primary targets of the cyber campaign.

To mitigate the risk, NITDA urged Nigerians never to paste commands from websites into their computers, stressing that legitimate software providers do not request such actions.

The agency also warned against opening files labelled “Chrome Setup” or “Firefox Installer” from USB drives and advised users to scan all external devices with updated antivirus software before use.

Among other recommendations, NITDA urged individuals to enable two-factor authentication on important accounts and avoid saving banking credentials in web browsers.

For organisations, the agency advised immediate staff sensitisation on the DeepLoad threat, activation of PowerShell Script Block Logging on Windows systems, and regular reviews of browser extensions to identify and remove unauthorised installations.

NITDA further directed organisations to block identified malicious domains, including “holiday-updateservice[.]com”, “forest-entity[.]cc”, and “hell1-kitty[.]cc”, at firewall and DNS levels.

The agency also urged IT administrators to inspect systems for hidden WMI Event Subscriptions, warning that standard malware cleanup procedures may fail to completely remove the threat.

In cases of suspected infection, NITDA advised affected individuals and organisations to immediately disconnect compromised systems from the internet, change passwords using clean devices, isolate affected networks and activate incident response procedures.

The agency reminded organisations that cybersecurity incidents must be reported to NITDA within 72 hours in compliance with existing regulations.

NITDA referenced findings from international cybersecurity reports published between March and April 2026 by cybersecurity firms and technology publications, including ReliaQuest, Infosecurity Magazine, The Hacker News and SOC Prime, all of which highlighted DeepLoad’s use of AI-generated evasion techniques and credential theft operations.

+ posts

Amanze Chinonye is a Staff Correspondent at Prime Business Africa, a rising star in the literary world, weaving captivating stories that transport readers to the vibrant landscapes of Nigeria and the rest of Africa. With a unique voice that blends with the newspaper's tradition and style, Chinonye's writing is a masterful exploration of the human condition, delving into themes of identity, culture, and social justice. Through her words, Chinonye paints vivid portraits of everyday African life, from the bustling markets of Nigeria's Lagos to the quiet villages of South Africa's countryside . With a keen eye for detail and a deep understanding of the complexities of Nigerian society, Chinonye's writing is both a testament to the country's rich cultural heritage and a powerful call to action for a brighter future. As a writer, Chinonye is a true storyteller, using her dexterity to educate, inspire, and uplift readers around the world.

Amanze Chinonye

Amanze Chinonye is a Staff Correspondent at Prime Business Africa, a rising star in the literary world, weaving captivating stories that transport readers to the vibrant landscapes of Nigeria and the rest of Africa. With a unique voice that blends with the newspaper's tradition and style, Chinonye's writing is a masterful exploration of the human condition, delving into themes of identity, culture, and social justice. Through her words, Chinonye paints vivid portraits of everyday African life, from the bustling markets of Nigeria's Lagos to the quiet villages of South Africa's countryside . With a keen eye for detail and a deep understanding of the complexities of Nigerian society, Chinonye's writing is both a testament to the country's rich cultural heritage and a powerful call to action for a brighter future. As a writer, Chinonye is a true storyteller, using her dexterity to educate, inspire, and uplift readers around the world.

Previous Story

Tegbe Promises To Stabilise Nigeria’s Power Grid Within 100 Days

Next Story

Nigeria, South Africa Seek to Ease Tensions Amid Rising Xenophobic Attacks

Featured Stories

Latest from Data & Infographics

Clothing market

Most Nigerians Earn ₦50,000 or Less Monthly – Report

Written by Amanze Chinonye A new financial services market report has revealed that most Nigerians survive on modest monthly incomes, with more than two-thirds earning ₦50,000 or less, underscoring deep-seated income challenges in the country. According to The Nigerian Financial Services Market Report
Previous Story

Tegbe Promises To Stabilise Nigeria’s Power Grid Within 100 Days

Next Story

Nigeria, South Africa Seek to Ease Tensions Amid Rising Xenophobic Attacks

Don't Miss

Nigeria, Indonesia Join U.S., China, India As Emerging Global Powers By 2050 – Report

The World Population Review has listed Nigeria and Indonesia alongside
Financial deficit

Nigeria Records N13.5trn Deficit In 2023 As Debt Servicing Gulps 43.9%

Nigeria recorded a deficit of N13.50 trillion in the 2023