New wormable Android malware discovered through auto-replies in WhatsApp

Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being.

Check Point Research has discovered new malware on Google’s Play Store that could spread through WhatsApp messages. 

According to the cybersecurity firm, the malware was designed with the ability to automatically respond to incoming WhatsApp messages on behalf of its victims, and the content of the response was provided by a remote server. 

CPR found the malware hidden in a fake “Netflix” application on Play Store called FlixOnline, which promised “unlimited entertainment” from anywhere in the world.

If successful, the malware enables its threat actors to perform a range of malicious activities, such as:

  • Spread further malware via malicious links
  • Steal credentials and data from users’ WhatsApp accounts
  • Spread fake or malicious messages to users’ WhatsApp contacts and groups – for example, work-related groups


The malware was designed to be wormable, meaning it can spread from one Android device to another after the Android user clicks on the link in the message and downloads the malware. 

How the Malware Works

1.      Victim installs the malware from Google’s Play Store

2.      The malware starts to “listen” for new notifications on WhatsApp

3.      Malware responds to every WhatsApp message the victim receives with a response crafted by the threat actors

4.      In this campaign, the response was a fake Netflix site that phished for credentials and credit card information

The Scripted WhatsApp Message

The malware sent the following automatic response to its victims incoming WhatsApp messages, attempting to lure others with the offer of a free Netflix service:  

“2 Months of Netflix Premium Free at no cost For REASON OF QUARANTINE (CORONA VIRUS)* Get 2 Months of Netflix Premium Free anywhere in the world for 60 days. Get it now HERE https://bit[.]ly/3bDmzUw”.

Disguised in a Fake “Netflix” Application

CPR found the malware hidden within an application on Google Play called ’FlixOnline.’” The app turned out to be a fake service that claims to allow users to view Netflix content from around the world on their mobiles. However, instead of allowing the mobile user to view Netflix content, the application is…