By Naledi Nyoni
HARARE — A Midlands State University (MSU) final-year Computer Science student has appeared in court accused of using malware to hack into CABS systems and steal more than US$1.1 million through thousands of fraudulent transactions.
Sabelo Malunga, 24, allegedly infiltrated the bank’s computer systems while working as an IT intern between November last year and February 23.
Prosecutors allege that on January 23, Malunga used a CABS-issued laptop to secretly download SUPREMO, a remote-access application, without authorisation.
He allegedly concealed the software within system files to evade detection.
After his internship ended, Malunga allegedly continued accessing the bank’s systems remotely, using the malware to bypass internal controls and create fraudulent ZIPIT and VISA transactions.
CABS only discovered the cyberattack on March 27 after VISA flagged two suspicious international ATM transactions.
The bank blocked the affected accounts, but US$210,500 had already allegedly been lost.
Further investigations on April 13 uncovered multiple malware infections on CABS servers.
Investigators allegedly found 1,911 fraudulent ZIPIT transactions worth US$925,679, with the money transferred to EcoCash, InnBucks, CBZ and Ecobank accounts.
CABS subsequently hired South African digital forensics firm MWR to investigate the breach and remove the malware.
Forensic investigators allegedly linked Malunga to the attack.
Prosecutors allege the malware enabled the accused to bypass authorisation systems, generate fictitious transfers and create fake telegraphic transfers, allowing him to siphon money from the bank.
CABS’ alleged total loss stands at US$1,136,179, with nothing recovered so far.
Malunga is facing a hacking charge and was remanded in custody pending his bail application on Monday.