Security News > 2022 > October > Unofficial WhatsApp Android app caught stealing users’ accounts

Unofficial WhatsApp Android app caught stealing users’ accounts
2022-10-12 18:56

A new version of an unofficial WhatsApp Android application named 'YoWhatsApp' has been found stealing access keys for users' accounts.

YoWhatsApp is a fully working messenger app that uses the same permissions as the standard WhatsApp app and is promoted through advertisements on popular Android applications like Snaptube and Vidmate.

According to a report published today, the modded app sends users' WhatsApp access keys to the developer's remote server.

Like the real WhatsApp Android app, the malicious app requests permissions, like accessing SMS, which is also granted to the Triada Trojan that's embedded in the app.

The malicious app offers additional features like a customizable interface, individual chat room blocks, and other stuff not available on the WhatsApp client but many people would like to have.

This month, Meta sued several Chinese companies doing business as HeyMods, Highlight Mobi, and HeyWhatsApp for developing "Unofficial" WhatsApp apps that stole over one million WhatsApp accounts.


News URL

https://www.bleepingcomputer.com/news/security/unofficial-whatsapp-android-app-caught-stealing-users-accounts/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Whatsapp 5 1 23 14 1 39
Android 4 0 17 2 0 19