HARARE – A Midlands State University final-year computer science student allegedly used malware and a remote-access application to siphon more than US$1.1 million from CABS through fraudulent VISA, ZIPIT and other transactions, a Harare court heard.
Sabelo Malunga, 24, appeared before regional magistrate Francis Mapfumo on charges of hacking.
He was remanded in custody to Thursday for a bail hearing.
The National Prosecuting Authoriy, led by prosecutor Blessed Songozo, alleges that Malunga exploited access to CABS’ banking systems during and after an internship at the bank between November last year and February 23 this year.
The alleged breach came to light in March after VISA flagged two suspicious international ATM transactions involving CABS-issued debit cards.
CABS blocked the affected accounts but had already suffered a loss of US$210,500. Nothing was recovered.
The court heard that during an internal investigation on April 13, the bank’s IT team discovered multiple malware infections on its servers.
Further analysis allegedly showed that the malware was being used to create fraudulent ZIPIT transactions and inject them directly into Zimswitch, bypassing CABS’ internal controls.
A subsequent reconciliation uncovered 1,911 fraudulent ZIPIT transactions worth US$925,679, allegedly routed to EcoCash, InnBucks, CBZ and Ecobank.
CABS then engaged South African digital forensics firm MWR to contain and remove the malware and investigate the breach.
According to the forensic report, investigators allegedly linked Malunga to the attack.
The State alleges that on January 23, while still an intern and using a CABS-issued laptop, Malunga downloaded a remote-access application called SUPREMO without authorisation.
He allegedly hid the application among system files to evade detection.
Prosecutors said SUPREMO gave Malunga the ability to remotely access CABS’ data and computer systems.
The State further alleges that Malunga continued accessing the bank’s systems after his internship ended on February 23.
He is accused of deploying malware that allowed transactions to be authorised unlawfully, ZIPIT transfers to be injected into Zimswitch, fictitious transactions to be routed to Ecobank through an integration, and fake telegraphic transfers to be generated.
The State alleges that the various transactions resulted in CABS suffering an actual loss of US$1,136,179.
Nothing has been recovered so far.
Malunga has not yet been asked to plead to the allegations.













