{"id":1246,"date":"2025-08-01T14:25:36","date_gmt":"2025-08-01T13:25:36","guid":{"rendered":"https:\/\/zerothcode.com\/blog\/?p=1246"},"modified":"2025-08-01T14:25:36","modified_gmt":"2025-08-01T13:25:36","slug":"modified-whatsapp-app-caught-infecting-android-devices-malware","status":"publish","type":"post","link":"https:\/\/zerothcode.com\/blog\/modified-whatsapp-app-caught-infecting-android-devices-malware\/","title":{"rendered":"Modified WhatsApp App Caught Infecting Android Devices with Malware"},"content":{"rendered":"<figure style=\"width: 728px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/thehackernews.com\/new-images\/img\/b\/R29vZ2xl\/AVvXsEi13K0uQ5xGIHnqtZwSYndbB0dp5TcOGRu2fvuyjlvtEnfuar1TxwX4EJBkIX9KReG6oKvvLqQf7ClXYmQJqwaNpZnG0a9t5xvizFCORipmYuTiWZozoUKELQYBEMPpV6OUaftBmVo77I0h-HAIWliAfAJnPTrwMVg9Jpr77X0-t5d4YGlxT_pA68B9\/s728-e1000\/whatsapp.jpg\" alt=\"WhatsApp Malware\" width=\"728\" height=\"380\" \/><figcaption class=\"wp-caption-text\">WhatsApp Malware<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>An unofficial version (WhatsApp Malware) of the popular WhatsApp messaging app called <b>YoWhatsApp\u00a0<\/b>has been observed deploying an Android trojan known as Triada.<\/p>\n<p>The goal of the malware is to steal the keys that &#8220;allow the use of a WhatsApp account\u00a0<a href=\"https:\/\/github.com\/tgalal\/yowsup\" target=\"_blank\" rel=\"noopener\">without the app<\/a>,&#8221; Kaspersky said in a new report. &#8220;If the keys are stolen, a user of a malicious WhatsApp mod can lose control over their account.&#8221; WhatsApp Malware<\/p>\n<p>YoWhatsApp offers the ability for users to lock chats, send messages to unsaved numbers, and customize the app with a variety of theming options. It&#8217;s also said to share overlaps with other modded WhatsApp clients such as FMWhatsApp and HeyMods. WhatsApp Malware<\/p>\n<p>WhatsApp Malware &#8211; The Russian cybersecurity company said it found the malicious functionality in YoWhatsApp version 2.22.11.75.<\/p>\n<figure style=\"width: 728px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/thehackernews.com\/new-images\/img\/b\/R29vZ2xl\/AVvXsEhqojJU6Taf2z-RjubJxLO-frRFx5Y6E6To3R2kgRouzTxvzSVXUjy8ODWMYsSemi92kioHMVcDZPTqW2SDW6fe0y4MGuEUfVsJyYg6lDAFFiCimwJoEWUq23BImOuMCRNJwfZsHYXYgDPC9AJkjI-yddCPHSgZ5X7nJccUpJ0NOba_GK5ajUFfHege\/s728-e1000\/hack.jpg\" alt=\"WhatsApp Malware\" width=\"728\" height=\"384\" \/><figcaption class=\"wp-caption-text\">WhatsApp Malware<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>Typically spread through fraudulent ads on Snaptube and Vidmate, the app, upon installation, requests the victims to grant it permissions to access SMS messages, enabling the malware to enroll them to paid subscriptions without their knowledge.<\/p>\n<p>A successful theft of the keys can lead to a total compromise of the account, allowing the adversary to access chat messages and even impersonate the victim to send malspam and conduct financial fraud. WhatsApp Malware<\/p>\n<p>The development comes amid Meta Platforms\u00a0filing a lawsuit\u00a0against three developers in China and Taiwan for distributing unofficial WhatsApp apps, including HeyMods, that resulted in the compromise of over one million user accounts.<\/p>\n<p>The findings also arrive a little over a year after threat actors were found delivering the Triada malware through FMWhatsApp. WhatsApp Malware<\/p>\n<p>&#8220;Cybercriminals are increasingly using the power of legitimate software to distribute malicious apps,&#8221; the researchers pointed out. &#8220;This means that users who choose popular apps and official installation sources, may still fall victim to them.&#8221;<\/p>\n<blockquote class=\"wp-embedded-content\" data-secret=\"dbBHdaE1u6\"><p><a href=\"https:\/\/zerothcode.com\/blog\/apple-removes-macos-macos-security\/\">Apple Removes macOS Feature That Allowed Apps to Bypass Firewall Security<\/a><\/p><\/blockquote>\n<p><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; visibility: hidden;\" title=\"&#8220;Apple Removes macOS Feature That Allowed Apps to Bypass Firewall Security&#8221; &#8212; ZEROTHCODE\" src=\"https:\/\/zerothcode.com\/blog\/apple-removes-macos-macos-security\/embed\/#?secret=Ni4avqFLRB#?secret=dbBHdaE1u6\" data-secret=\"dbBHdaE1u6\" width=\"600\" height=\"338\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; An unofficial version (WhatsApp Malware) of the popular WhatsApp messaging app called YoWhatsApp\u00a0has been observed deploying an Android trojan<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[37],"tags":[],"yst_prominent_words":[238,1188,495,307,1158,71,179,115,496,170,1404],"class_list":["post-1246","post","type-post","status-publish","format-standard","hentry","category-hackers-news"],"_links":{"self":[{"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/posts\/1246","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/comments?post=1246"}],"version-history":[{"count":1,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/posts\/1246\/revisions"}],"predecessor-version":[{"id":1297,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/posts\/1246\/revisions\/1297"}],"wp:attachment":[{"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/media?parent=1246"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/categories?post=1246"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/tags?post=1246"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/yst_prominent_words?post=1246"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}