Malware & RansomwareHIGH

WhatsApp Alerts Users of Fake App Containing Spyware

Featured image for WhatsApp Alerts Users of Fake App Containing Spyware
TCTechCrunch Security+1 more
WhatsAppSIOSpyrtacusspywareItalycybersecuritymalwaresocial engineeringprivacy
🎯

WhatsApp has told about 200 users that they accidentally downloaded a fake version of the app that had spyware in it. This fake app was made by a company in Italy called SIO. WhatsApp is making sure these users are safe and reminding everyone to only download the real app.

Quick Summary

WhatsApp has warned users about a fake app containing spyware, primarily affecting users in Italy. The incident highlights ongoing security threats and the use of social engineering tactics.

WhatsApp has alerted approximately 200 users who were deceived into installing a malicious imitation of its messaging app, which was embedded with spyware. The Meta subsidiary claims that this counterfeit version was specifically designed for iPhones by the Italian spyware manufacturer SIO. Most of the affected users are located in Italy. In a recent announcement, WhatsApp stated, "We assess that the threat actors behind this malicious client used social engineering tactics to trick people outside of our app into downloading their malicious software masquerading as WhatsApp." The company reassured users that this incident does not stem from any vulnerability within WhatsApp, as end-to-end encryption continues to safeguard communications for those using the official app. WhatsApp has logged out the affected users and urged them to uninstall the fake app and download the legitimate version. The security team at WhatsApp identified the dummy app proactively and attributed its creation to SIO's subsidiary, ASIGINT. SIO has a history of collaborating with law enforcement and intelligence agencies, as noted on its website. The social engineering tactics employed in this incident were described as "highly targeted," though WhatsApp did not disclose specific details about the victims. This incident follows a previous alert from WhatsApp last year, when around 90 users were notified of being targeted with spyware from Paragon Solutions. Notably, Paragon ended its contract with Italy after the government restricted its ability to verify the use of spyware against a prominent journalist. WhatsApp has also taken legal action against spyware maker NSO Group, which was found liable for targeting users with its Pegasus tool.

The use of social engineering tactics to distribute spyware through fake apps underscores the importance of user education regarding app downloads. As spyware technology evolves, so too must the strategies to combat it, including legal actions against firms like SIO and Paragon Solutions.

Original article from

TCTechCrunch Security· Lorenzo Franceschi-Bicchierai
Read Full Article

Also covered by

THThe Record

WhatsApp warns users of fake app used to distribute spyware

Read Article

Related Pings

HIGHMalware & Ransomware

Linux Rootkit Detection - Importance of Behavioral Analysis

Rootkits in Linux systems are a growing threat, exposing the weaknesses of static detection methods. This article discusses how behavioral detection can enhance security. Discover techniques to better protect your systems against these stealthy attacks.

Elastic Security Labs·
HIGHMalware & Ransomware

Ransomware - New Cybercrime Service Promotes Data Monetization

A new cybercrime service is promoting the sale of data stolen from ransomware attacks. This could lead to more victims facing extortion. Experts are divided on its potential success.

SC Media·
HIGHMalware & Ransomware

CrystalRAT Malware - New Features Include Prankware and Theft

CrystalRAT malware is making waves with its remote access and data theft capabilities. Users of popular browsers and apps are at risk. Stay alert and avoid suspicious downloads to protect your data.

BleepingComputer·
HIGHMalware & Ransomware

Malware Campaign Uses WhatsApp to Deliver Malicious VBS Files

A new malware campaign is leveraging WhatsApp to deliver malicious VBS files via trusted cloud platforms. Organizations are at risk as attackers blend into normal operations, making detection challenging. Security experts recommend proactive measures to combat this evolving threat.

SC Media·
HIGHMalware & Ransomware

NoVoice Android Malware - Infected 2.3 Million Devices

A new Android malware named NoVoice has infected over 2.3 million devices via Google Play. This malware targets WhatsApp data, posing serious security risks. Users must take immediate action to secure their devices and data.

BleepingComputer·
HIGHMalware & Ransomware

CERT-UA Impersonation - Malware Campaign Targets 1 Million Emails

A new phishing campaign impersonating CERT-UA has spread AGEWHEEZE malware to over 1 million emails. This attack targeted various sectors, raising serious security alarms. Stay vigilant against such threats to protect your data.

The Hacker News·