The Nigeria Computer Emergency Response Team (ngCERT) has issued a cybersecurity advisory warning Nigerians against downloading free Virtual Private Network (VPN) applications and other untrusted software, saying some of the seemingly harmless apps are secretly converting users’ devices into tools for cybercriminals.
The alert is aimed at protecting Nigerian internet users from a growing cyber threat in which malicious software disguises itself as legitimate applications while quietly hijacking victims’ internet connections for criminal activities.
The advisory, according to ngCERT, responds to the increasing sophistication of streaming piracy networks and malware campaigns that target individuals, businesses and organisations by embedding malicious software development kits (SDKs) inside free VPNs, utilities and similar applications.
The cybersecurity agency identifies several malicious SDKs, including Hex SDK, Packet SDK, Castar SDK and Earn SDK, as components used to compromise unsuspecting users’ devices.

By exploiting legitimate residential internet connections, attackers can conceal their identities while carrying out cyberattacks, making it more difficult for law enforcement agencies and security researchers to trace the true source of malicious activity.
Once installed, the malware silently converts an internet-connected device into what cybersecurity experts describe as a residential proxy exit node, allowing cybercriminals to route malicious internet traffic through a victim’s connection without the owner’s knowledge or consent.
By exploiting legitimate residential internet connections, attackers can conceal their identities while carrying out cyberattacks, making it more difficult for law enforcement agencies and security researchers to trace the true source of malicious activity.
According to ngCERT, one of the proxy infrastructures facilitating the attacks is IPIDEA, a residential proxy network that has been widely abused by more than 550 cyber threat groups worldwide.
The agency says compromised devices have been used to support botnet command-and-control operations, credential stuffing attacks, cyber espionage campaigns and efforts to disguise the origins of malicious internet traffic.
“The infection,” ngCERT says in the advisory, “affects millions of devices globally and exposes victims to secondary risks such as bandwidth abuse, network compromise, and potential legal implications from illicit traffic routed through their connections.”
VPN: Illegal streaming apps pose additional risks
Beyond free VPN services, ngCERT also warns Nigerians against downloading illegal streaming applications that promise low-cost or free access to premium digital content.
The advisory cites Cinemagoal as an example of applications that provide unauthorised access to subscription-based services such as Netflix, Disney+, Spotify and Sky through fraudulently obtained credentials.
According to the agency, these applications often connect users’ devices to foreign servers using compromised accounts, virtual machines and false digital identities, exposing unsuspecting users to malware infections and credential theft.
The advisory cites Cinemagoal as an example of applications that provide unauthorised access to subscription-based services such as Netflix, Disney+, Spotify and Sky through fraudulently obtained credentials.
With Nigeria’s digital ecosystem continuing to expand, ngCERT says growing adoption of such illicit applications increases the country’s exposure to cybercrime by turning ordinary consumer devices into potential launch points for larger attacks.
The agency warns that infected devices can unknowingly become part of organised cybercrime infrastructure, weakening Nigeria’s overall cybersecurity posture and creating opportunities for financial fraud, identity theft and other forms of online crime.
How Nigerians can protect themselves
According to ngCERT, victims of these malicious applications may unknowingly allow criminals to use their internet bandwidth and residential IP addresses for illegal activities, expose home and office networks to external attackers, participate in botnets without their knowledge and experience degraded device performance alongside excessive data consumption.
The agency also cautions that internet subscribers could suffer reputational damage or even face legal scrutiny if criminal activities are traced to their internet connections.
To minimise these risks, ngCERT advises Nigerians to:
- Avoid downloading free VPNs, utilities and applications from untrusted sources.
- Use legitimate paid VPN services from reputable providers where privacy tools are required.
- Regularly scan devices using trusted antivirus and anti-malware software.
- Enable Google Play Protect on Android devices.
- Review installed applications for suspicious software.
- Monitor network activity for unusual behaviour.
- Keep operating systems and applications updated with the latest security patches.
For organisations, the agency recommends deploying Endpoint Detection and Response (EDR) solutions, strengthening network monitoring capabilities and proactively detecting proxy-like behaviour before attackers can exploit compromised systems.
The latest advisory underscores ngCERT’s broader effort to protect Nigerians from increasingly sophisticated cyber threats as internet adoption, digital payments and online services continue to expand across the country. By encouraging safer software choices and stronger cyber hygiene, the agency aims to reduce the risk of ordinary internet users unknowingly becoming accomplices in global cybercrime operations.





























Home