Malware & RansomwareHIGH

WhatsApp Alerts Users of Fake App Containing Spyware

Featured image for WhatsApp Alerts Users of Fake App Containing Spyware
TCTechCrunch SecurityΒ·Reporting by Lorenzo Franceschi-Bicchierai
πŸ“° 7 sourcesΒ·Summary by CyberPings EditorialΒ·AI-assistedΒ·Reviewed by Rohit Rana
Updated:
🎯

WhatsApp found out that some people downloaded a fake version of its app that had spyware in it. They told those users to delete the fake app and use the real one instead. The fake app was made by a company that sells spying tools to the government.

Quick Summary

WhatsApp has alerted users about a fake app that contained spyware, created by the Italian firm SIO. The company is taking legal action to prevent further distribution of such malicious software.

What Happened

WhatsApp has alerted approximately 200 users who were misled into downloading a counterfeit version of its iOS app, which was infected with spyware. The malicious app was created by SIO, an Italian spyware manufacturer, and primarily targeted users in Italy. WhatsApp's security team proactively identified the threat and logged out the affected users, advising them to uninstall the fake app and download the official version.

Who's Affected

The majority of the impacted users are located in Italy, although WhatsApp has not disclosed specific identities or whether the victims include journalists or civil society members. The company emphasized that this incident did not stem from a vulnerability in WhatsApp itself, as end-to-end encryption continues to protect users of the official app.

The Flaw

The counterfeit app utilized social engineering tactics to deceive users into installing it, masquerading as the legitimate WhatsApp application. This tactic is part of a broader strategy employed by SIO, which markets its spyware solutions to law enforcement and intelligence agencies.

What's at Risk

Users who installed the fake app risked exposure of their personal data and communications, which could be monitored by the spyware embedded within the counterfeit application. The spyware, identified as Spyrtacus, has been linked to previous incidents involving malicious Android applications that also targeted users under the guise of legitimate services.

In response to this breach, WhatsApp is pursuing legal action against SIO and its subsidiary ASIGINT for creating and distributing the malicious app. This follows a pattern of similar incidents where SIO has been implicated in deploying spyware via counterfeit applications.

Immediate Actions

WhatsApp has taken immediate steps to protect its users by logging them out of the malicious app and sending alerts regarding the risks associated with downloading unofficial clients. Users are strongly encouraged to uninstall any suspicious applications and ensure they are using the official WhatsApp app to maintain their privacy and security.

Context

This incident follows a troubling trend in Italy, where government agencies have been known to collaborate with cellphone providers to distribute phishing links to users. The use of spyware against targeted individuals, including journalists and human rights advocates, has raised significant concerns about privacy and surveillance practices in the country. Just last year, WhatsApp notified around 90 users about being targeted by spyware from Paragon Solutions, highlighting ongoing issues with surveillance technology in Europe.

The use of counterfeit applications to distribute spyware is a growing concern, particularly in regions like Italy where surveillance practices are prevalent. Users must remain vigilant about the apps they install and ensure they are downloading from trusted sources.

Original article from

TCTechCrunch SecurityΒ· Lorenzo Franceschi-Bicchierai
Read Full Article

Also covered by

THThe Record

WhatsApp warns users of fake app used to distribute spyware

Read Article
THThe Hacker News

WhatsApp Alerts 200 Users After Fake iOS App Installed Spyware; Italian Firm Faces Action

Read Article
SCSC Media

WhatsApp warns of spyware in fake iPhone app

Read Article
SESecurity Affairs

Italian spyware vendor creates Fake WhatsApp app, targeting 200 users

Read Article
CYCyber Security News

WhatsApp Warns Users Targeted by Spyware Attack via Weaponized Version of the App

Read Article
CYCyberWire Daily

The WhatsApp impostor.

Read Article

Related Pings

HIGHMalware & Ransomware

Malware Newsletter Round 91 - Latest Threats and Insights

The latest malware newsletter reveals new threats like Infiniti Stealer and npm supply chain attacks. Developers and organizations must stay alert to evolving risks in cybersecurity.

Security AffairsΒ·
HIGHMalware & Ransomware

Malicious Email Delivers CMD Malware - Privilege Escalation Alert

A malicious email has delivered a .cmd malware file that escalates privileges and bypasses antivirus systems. Users are at risk of significant system compromise. Awareness and immediate action are vital to mitigate this threat.

Security AffairsΒ·
HIGHMalware & Ransomware

Axios NPM Package Compromised - Supply Chain Attack Exposed

A major supply chain attack compromised the Axios NPM package, affecting millions of users. Malicious versions deployed a RAT, posing serious security risks. Swift action was taken to remove the threats.

Trend Micro ResearchΒ·
HIGHMalware & Ransomware

Brokk Hacked - Play Ransomware Exposes Sensitive Data

Brokk has reportedly been hacked by Play ransomware, leading to the leak of sensitive corporate data. This incident could severely impact the company's reputation and security. Organizations must bolster their defenses to prevent similar breaches.

SC MediaΒ·
HIGHMalware & Ransomware

Chaos Malware - New Targeting of 64-bit Linux Servers

Chaos malware has evolved to target 64-bit Linux servers, expanding its attack surface. This shift raises alarms for organizations relying on these systems. Enhanced security measures are now crucial to protect against potential larger-scale attacks.

SC MediaΒ·
HIGHMalware & Ransomware

Phorpiex Botnet - Spreading Ransomware and Sextortion Tactics

The notorious Phorpiex botnet is back, spreading ransomware and sextortion schemes. Millions are at risk as it targets users globally. Stay alert and protect your devices from this evolving threat.

Cyber Security NewsΒ·