Security News > 2021 > January > Beware — A New Wormable Android Malware Spreading Through WhatsApp
A newly discovered Android malware has been found to propagate itself through WhatsApp messages to other contacts in order to expand what appears to be an adware campaign.
"This malware spreads via victim's WhatsApp by automatically replying to any received WhatsApp message notification with a link to [a] malicious Huawei Mobile app," ESET researcher Lukas Stefanko said.
Once installed, the wormable app prompts victims to grant it notification access, which is then abused to carry out the wormable attack.
In its current version, the malware code is capable of sending automatic replies only to WhatsApp contacts - a feature that could be potentially extended in a future update to other messaging apps that support Android's quick reply functionality.
While the message is sent only once per hour to the same contact, the contents of the message and the link to the app are fetched from a remote server, raising the possibility that the malware could be used to distribute other malicious websites and apps.
"I don't remember reading and analyzing any Android malware having such functionality to spread itself via whatsapp messages," Stefanko told The Hacker News.
News URL
Related news
- Week in review: VMware ESXi zero-day exploited, SMS Stealer malware targeting Android users (source)
- New LianSpy malware hides by blocking Android security feature (source)
- Android malware uses NFC to steal money at ATMs (source)
- New NGate Android malware uses NFC chip to steal credit card data (source)
- Cybercriminals Deploy New Malware to Steal Data via Android’s Near Field Communication (NFC) (source)
- New Android Malware NGate Steals NFC Data to Clone Contactless Payment Cards (source)
- SpyAgent Android malware steals your crypto recovery phrases from images (source)
- New Android SpyAgent Malware Uses OCR to Steal Crypto Wallet Recovery Keys (source)
- Beware: New Vo1d Malware Infects 1.3 Million Android-based TV Boxes Worldwide (source)
- New Android Malware 'Ajina.Banker' Steals Financial Data and Bypasses 2FA via Telegram (source)