An unofficial WhatsApp app has been stealing access keys for users’ accounts.
The app, called ‘Yo WhatsApp’, was promoted through ads in other Android applications such as Snaptube, which allows users to download YouTube videos – promoting itself with features Meta’s own client does not such as the ability to customise the user experience or individual chat room blocking.
The fraudulent app was discovered by Kaspersky, who found that the app sent users’ WhatsApp access keys to the developer’s remote server.
This could allow attackers to see conversations and steal data that could be used for phishing or other cyberattacks. Moreover, the attackers could use this access to “add paid subscriptions without the user’s knowledge”.
A clone of that app, called “WhatsApp Plus”, also spread through the Vidmate app, with similar features and issues. Vidmate also lets users download YouTube, Instagram, Facebook, and TikTok videos.
Vidmate and Snaptube did not respond to The Independent’s request for comment before time of publication.
Kaspersky suggests that the distribution channels will be closed soon, and says it is likely the companies were unaware malware was being shared.
“Cybercriminals are increasingly using the power of legitimate software to distribute malicious apps. This means that users who choose popular apps and official installation sources, may still fall victim to them”, the Kaspersky researchers wrote.
“In particular, malware like Triada can steal an IM account, and for example, use it to send unsolicited messages, including malicious spam. The user’s money is also at risk, as the malware can easily set up paid subscriptions for the victim.”
Kaspersky has been investigating the Trida malware in WhatsApp clones over the past year and is especially difficult to detect for two reasons: firstly, the malware modifies a core process in the Android OS that is used as a template for every application, called Zygote. When the Trojan gets into Zygote, it becomes a part of every app that is launched on the device.
Secondly, the app substitutes the phone’s system functions, concealing its modules from the list of the running processes and installed apps – which stops its processes being detected and thereby stays unknown.