WhatsApp warns iPhone users of fake app distributing potent spyware

April 2, 20262 min read1 sources
Share:
WhatsApp warns iPhone users of fake app distributing potent spyware

Meta has issued a warning to WhatsApp users about a malicious counterfeit version of its application designed to install spyware on iPhones. The company alleges the fake app was created by SIO, an Italian commercial surveillance firm, to deploy sophisticated spyware against a targeted group of users, primarily located in Italy.

The warning was detailed in Meta's Q3 2023 Adversarial Threat Report. According to the report, the attack does not exploit a vulnerability in WhatsApp itself. Instead, it relies on social engineering to trick individuals into downloading and installing the malicious application from a source outside of Apple's official App Store, a practice known as side-loading. These deceptive links are often sent via text message or email.

Once installed, the application deploys spyware, believed to be a variant of "Hermit." This malware gives attackers extensive control over an infected device. Its capabilities include exfiltrating call logs, contacts, photos, and location data. The spyware can also secretly activate the device's microphone to record ambient audio and steal data from other messaging applications.

Meta stated it has taken action to disrupt SIO's infrastructure and has removed accounts associated with the firm from its platforms. This incident is part of a wider effort by major tech companies to combat the growing surveillance-for-hire industry, which sells powerful hacking tools to government agencies.

Users are strongly advised to download applications only from official sources like the Apple App Store or Google Play Store. Scrutinizing unsolicited links, even if they appear to be from a trusted contact, remains a critical defense. While a VPN cannot prevent malware installation from a deceptive link, it is a foundational tool for encrypting internet traffic and masking a user's location from other online threats.

Share:

// SOURCES

// RELATED

Russian money launderer for TrickBot ransomware group sentenced to two years

Denis Dubnikov, a Russian national, has been sentenced for laundering over $400,000 for the notorious TrickBot cybercrime group.

2 min readApr 3

Apple expands iOS 18.7.7 update to block sophisticated DarkSword exploit

Apple has broadened the availability of iOS 18.7.7, patching critical zero-click vulnerabilities exploited by the sophisticated DarkSword surveillance

2 min readApr 3

Critical flaw in Langflow AI platform under attack

A critical code injection vulnerability in the Langflow AI framework is under active attack, with threat actors exploiting it within hours of disclosu

2 min readApr 2

FCC seeks to expand security blacklist, potentially impacting future router sales

The FCC is seeking public comment on expanding its "Covered List" criteria, a move that could pave the way for future restrictions on foreign-made rou

2 min readApr 2